FlashLoopAdapter Exploit Drains $305K from Aave Linked Safe Wallets
An attacker exploited a vulnerability in the FlashLoopAdapter contract on Ethereum, draining $305,000 from two Safe wallets linked to Aave. The exploit used a Morpho flash loan to repay approximately 1,335 WETH in Aave debt, freeing collateral tied to the leveraged position. The attacker then used the compromised module execution path to withdraw around 1,306 weETH from one of the wallets, valued at approximately $305,000 when the incident was reported.
Aave founder Stani Kulechov stated that the affected contract was a third-party external adapter built on top of Aave, with 'zero effect on Aave v3.'
The vulnerability concerned how the adapter authenticated callers and what they could make the enabled module execute. The attacker successfully bypassed the adapter's authentication logic by deploying a fake Safe contract, which passed the initial check and allowed the attacker to direct the adapter back toward the victim Safe and invoke its module execution function.
The incident highlights the importance of secure authentication mechanisms in smart contract design and the potential risks associated with third-party adapters and modules connected to Safe wallets.