FlashLoopAdapter Exploit Drains $305K from Two Aave-Linked Safes
A custom Ethereum module used to manage leveraged Aave V3 positions through Safe wallets was exploited on October 1, resulting in an estimated loss of about $305,000.
The affected component, known as FlashLoopAdapter, is a custom module built around Aave V3's leveraged-loop functionality. It provides an additional execution layer for leveraged Aave positions held through participating Safe wallets.
According to a security alert posted by Defimon Alerts on X, the module's authorization logic allowed an attacker-controlled contract to satisfy the conditions required to execute operations.
The attacker then used the module's execution path to interact with the affected Safes and withdraw collateral. Two Safe wallets were affected, with more than 1,300 weETH withdrawn from one of them.