FlashLoopAdapter Exploit Drains Over $300K from Aave-Linked Wallets
A recent exploit targeting an Aave-linked adapter drained over $305,000 from two Safe wallets on Ethereum. The hack, which occurred on October 2, took advantage of a weakness in FlashLoopAdapter, a contract used to manage leveraged positions on Aave V3.
The attacker bypassed the Safe authentication check and then used a Morpho WETH flash loan to repay debt and unlock collateral held by the affected wallets. This allowed them to drain around 114 ETH, worth roughly $305,000 to $310,000.
Aave founder Stani Kulechov stated that the incident did not affect Aave V3's core contracts, emphasizing that it was a third-party external adapter built on top of Aave. The stolen funds were later moved towards Tornado Cash, making them harder to trace.