FlashLoopAdapter Exploit Results in $305K Loss from Ethereum Safe Wallets
A custom module for managing Aave V3 leveraged positions on Ethereum's Safe platform was compromised in a security breach on October 1, resulting in approximately $305,000 in stolen assets.
The FlashLoopAdapter contract allowed hackers to bypass access verification protocols and extract collateral from two Safe wallets. The exploit incorporated a WETH flash loan borrowed from Morpho during the attack execution.
According to Defimon Alerts' analysis, the attacker initially settled 1,335 WETH in Aave debt obligations before extracting roughly 1,306.48 weETH from the first compromised wallet.