A FlashLoopAdapter exploit on Ethereum has left two Safe multisig wallets about 114 ETH poorer, roughly $305,000 at the time of the attack. The attacker didn't break Aave and didn't break Safe. They broke the small piece of code sitting between them. That third-party adapter was built to help users run leveraged Aave V3 positions, and its access checks could be fooled with a fake Safe.
Defimon Alerts first caught the attack at 15:08:57 UTC on October 1. SlowMist then published a breakdown on October 2, and the story kept spreading through crypto security feeds into this morning.
What Actually Happened
The FlashLoopAdapter was a custom Safe module. Users who wanted to loop their Aave V3 positions (borrow, re-deposit, borrow again) could enable it on their Safe wallet, and it would handle the steps for them.
The module was meant to accept calls only from Safes that had enabled it. That check turned out to be weak. According to SlowMist, the open() and close() functions had an access control flaw that let the attacker forge Safe authentication. A fake Safe passed checks meant only for real wallets with the module turned on.
From there, the attacker had what amounted to a remote control for the victims' positions.
How the Flash Loan Made It Work
Taking the collateral was the hard part. Aave doesn't let anyone pull collateral backing an open loan. So the attacker:
Took a WETH flash loan from Morpho.
Used it to repay about 1,335 WETH of Aave debt tied to the larger Safe.
Once the debt was cleared, used the compromised module to make that Safe withdraw about 1,306 weETH to an attacker-controlled address.
Swapped part of the weETH back into WETH to repay the flash loan within the same transaction.
A second Safe lost another 6.4 weETH through the same module. Defimon noted that both wallets had the same single owner.
After everything settled, the attacker kept about 114.09 ETH.
Why the 1,306 weETH Figure Is Misleading
Some early posts made this look like a much bigger theft. The 1,306 weETH was gross transaction flow, not profit. Most of that value went straight back out to repay the flash loan and close the leveraged position. The real loss to the victims is the roughly 114 ETH the attacker walked away with.
That's still a painful loss for one user. But it's a $305K story, not a multi-million-dollar one.
FlashLoopAdapter Exploit: Aave and Safe Say Core Protocols Are Safe
Aave founder Stani Kulechov responded quickly. He said the vulnerable contract was not an Aave V3 contract, but a third-party external adapter built on top of Aave, with no effect on Aave V3 itself.
Safe's core wallet contracts weren't compromised either. Safe modules are opt-in extensions, and the victims had chosen to enable this one. Once a module is trusted, it can act on the wallet's behalf without collecting the usual multisig signatures. That's the design. It's also why one bad module can undo the protection a multisig is supposed to give.
The market didn't panic. AAVE was trading around $182 with gains on the day while the news was spreading, which suggests traders saw this as a peripheral incident rather than a protocol-level one.
Bitnxt View: The Weak Link Is Almost Never the Big Name Anymore
At Bitnxt, we've seen this pattern often enough that it no longer surprises us. Aave V3 has been battle-tested for years. Safe secures billions. Attackers know that, so they go after the plugins, adapters and modules that users bolt on for convenience.
This isn't even the first Safe module incident this year. In May, a third-party module called SquidRouterModule, which had nothing to do with the official Squid Router protocol, was used to drain about $3.2 million from 86 Safe wallets on Ethereum and Base. The setup was similar: users trusted a module, and the module's authentication was weak. Last month's Bitget breach (Bitget Hacker Converts $6.3M to Bitcoin via THORChain) also started with a weakness in a third-party security product, not in Bitget's core wallet systems.
Our take is simple. A multisig is only as strong as the most permissive module attached to it. When a Safe module is enabled, it skips the signature process entirely, so users should treat that approval like handing over a spare key to the vault.
There's also a lesson for builders. Flash loans mean an attacker never needs their own capital. Any access control flaw, however small, can be scaled up with borrowed liquidity in a single transaction. Validating every caller, especially one claiming to be a trusted contract, isn't optional.
For a protocol that has just floated cutting back to its most productive chains (Aave Proposes Abandoning Six Blockchains That Generate Less Than $5,000 a Quarter), this incident is a reminder that Aave's wider ecosystem of integrations carries its own risk, even when the core protocol holds up.
What Users Should Do Now
Review the modules enabled on your Safe. If you don't recognize one or no longer use it, disable it.
Check whether third-party adapters are audited before giving them module-level permissions.
Don't confuse protocol branding with protocol code. An "Aave" loop tool or a "Squid" module isn't automatically built or endorsed by that team.
Keep an eye on official channels from SlowMist, Defimon and the affected teams for updates on fund tracing.
What Comes Next
So far there's no public word on a recovery or on whether the attacker has been contacted. Security firms are still tracking the funds. With DeFi exploits continuing to pile up, from the NEAR Intents exploit to the Tectonic exploit, the FlashLoopAdapter case adds weight to an uncomfortable trend: the core protocols are getting harder to break, but everything built around them is still fair game.
Bitnxt will update this story as more details emerge.













































