Skip to content
Back to Guavy Wire
Crypto

FlashLoopAdapter Exploit Drains $300K from Safe Wallets via Access-Control Flaw

Instruments
ETH AAVE
Share

A custom Ethereum module called FlashLoopAdapter was exploited on October 1, 2026, draining over $300,000 from two Safe wallets. The attacker used a WETH flash loan from Morpho to carry out the attack, repaying roughly 1,335 WETH in Aave debt and then withdrawing about 1,306.48 weETH from one wallet and 6.4 weETH from another.

The vulnerability was an access-control flaw in FlashLoopAdapter itself, not in Aave's underlying lending protocol. This distinction is crucial because the attack did not touch Aave's core contracts at all, but rather targeted a custom module used for managing leveraged positions.

The incident highlights the importance of secure coding practices and regular security audits, especially for modules and add-ons built on top of popular DeFi protocols like Aave. As more users rely on these tools to manage their leverage, it's essential that they understand the risks associated with custom modules and take steps to mitigate them.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc