A third-party lending tool built for Aave v3 was exploited on Oct. 2, resulting in the loss of 114.09 ETH worth over $300,000 from two Safe multisig wallets. Blockchain security firm SlowMist revealed that the underlying Aave v3 protocol remained completely secure during the attack, which targeted a flaw in an external adapter called FlashLoopAdapter.
Key Takeaways
- 114.09 ETH (worth over $300,000) was stolen from two Safe multisig wallets.
- Roughly 1,300 WETH of debt was repaid by the attacker to unlock collateral.
- Aave v3 core smart contracts were not compromised, leaving Aave's $33 billion in total value locked unaffected.
How the FlashLoopAdapter Vulnerability Was Exploited
According to SlowMist, the attacker targeted authentication checks inside the FlashLoopAdapter's open() and close() functions. These functions were designed to verify whether the calling Safe multisig had enabled the adapter module. However, the attacker deployed a fake Safe contract that returned positive responses to spoof authentication.
Once authentication was bypassed, the attacker exploited an arbitrary call weakness. The adapter permitted callers to define both the router address and calldata for external contract calls. By directing the router back to the victim Safe and injecting instructions for execTransactionFromModule, the attacker executed transactions through the victims' wallets to withdraw weETH and collateral linked to Aave positions. The attacker also repaid approximately 1,300 WETH in debt to release locked collateral.
Core Protocol Remains Unaffected
Aave founder Stani Kulechov clarified that the breach was strictly isolated to external tooling. "This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3," Kulechov stated. The distinction is crucial for Aave, which commands more than $33 billion in total value locked as the market's largest decentralized lending platform.
The incident reflects a broader trend in web3, where secondary integrations expose users to risks even when main protocol code is audited, contributing to how crypto hacks reach billions in losses. Similar vulnerabilities in smart contract tooling have prompted swift responses across the industry, such as when an Aurora co-founder gave a hacker 48 hours to return $3.8 million.
Why It Matters
This exploit highlights the ongoing perimeter risk facing decentralized finance applications. While top-tier protocols like Aave spend heavily on auditing core contracts, third-party yield optimizers, leverage tools, and adapter modules often introduce unvetted attack vectors. Investors using multisig security must carefully monitor which external modules hold execution privileges on their wallets to prevent unauthorized transaction execution.



