—
00:00
Money for You
Money for You
USD/RUB—
EUR/RUB—
Cryptocurrency

Exploit in Third-Party Aave Adapter Drains $305,000 from Safe Wallets

An authentication flaw in the FlashLoopAdapter, a tool designed to manage Aave v3 leveraged positions, allowed an attacker to drain approximately $305,000 from two Ethereum-based Safe wallets. The breach exploited a vulnerability in how the module verified the legitimacy of incoming transaction requests.

Exploit in Third-Party Aave Adapter Drains $305,000 from Safe Wallets

The incident, detected on October 1, centered on a custom contract that acted as an interface between user wallets and the Aave protocol. Security firm SlowMist identified the root cause as a spoofable access control check. The adapter’s open and close functions relied on a check that queried whether a caller was a legitimate Safe module. By deploying a malicious contract that mimicked a verified Safe, the attacker bypassed these security gates to gain unauthorized execution permissions.

Once inside, the attacker orchestrated a complex maneuver using a Morpho flash loan to settle 1,335 WETH of debt held by the primary victim wallet. This repayment unlocked over 1,300 weETH in collateral, which was subsequently withdrawn. A second wallet also suffered minor losses during the incident. After settling the flash loan, the attacker walked away with roughly 114 ETH, valued at $305,000.

Aave founder Stani Kulechov clarified that the exploit was confined to the third-party adapter, emphasizing that the core Aave v3 protocol remained secure and unaffected. This event mirrors previous security lapses involving Safe modules, where external integrations—rather than the primary wallets themselves—served as the point of failure. The vulnerability highlights the risks inherent in delegating transaction execution authority to modular smart contracts, which can effectively grant an attacker the ability to bypass standard owner controls if the authentication logic is flawed.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!