Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes

A custom Safe module used for Aave V3 leveraged positions was exploited through an access-control flaw, with collateral withdrawn from two affected wallets.

Written By Isha Chavda
Edited by Sujha Sundararajan
Published 2026-10-02·Updated 2 days ago
Make The Crypto Times preferred on GoogleGoogle
Conceptual representation of an Ethereum crypto transfer between two digital wallets with a hooded hacker and Aave v3 screen in the background.

Key Highlights

  • A FlashLoopAdapter module linked to Aave V3 leveraged loops was exploited for an estimated $305,000 loss.
  • The incident involved an access-control flaw in the custom module.
  • Two Safe wallets were affected, with more than 1,300 weETH withdrawn from one of them.

A custom Ethereum module used to manage leveraged Aave V3 positions through Safe wallets was exploited on October 1, resulting in an estimated loss of about $305,000.

According to a security alert posted by Defimon Alerts on X, the affected component, identified as FlashLoopAdapter, is designed to open and close leveraged Aave positions for Safe wallets that have enabled the module. 

🚨 FlashLoopAdapter (@aave v3 loop Safe module) – Loss $305K (2026-10-01)

Network: Ethereum
Type: Access Control

FlashLoopAdapter is a Safe module that opens/closes Aave v3 leveraged loops for the Safes that enable it. open()/close() trust any msg.sender that answers… pic.twitter.com/uFwSQ69Lpv

— Defimon Alerts (@DefimonAlerts) October 1, 2026

According to the alert, an attacker-controlled contract was able to pass the module’s access-control checks and use its execution path to move collateral from two affected Safes.

The reported weakness was in the custom FlashLoopAdapter contract built around Aave V3, rather than in Aave V3’s core lending contracts.

FlashLoopAdapter module exploited

FlashLoopAdapter provides an additional execution layer for leveraged Aave positions held through participating Safe wallets.

According to Defimon, its authorization logic allowed an attacker-controlled contract to satisfy the conditions required to execute operations.

The attacker then used the module’s execution path to interact with the affected Safes and withdraw collateral.

Two Safe wallets were affected

The security alert identified two affected Safe wallets.

In the first case, the transaction involved repayment of approximately 1,335 WETH of Aave debt, followed by the withdrawal of approximately 1,306.48 weETH from the Safe.

A second Safe lost approximately 6.4 weETH.

The attacker subsequently converted part of the withdrawn assets and retained approximately 114.1 ETH, according to the alert.

Defimon estimated the overall loss at approximately $305,000.

Etherscan shows 1,306.48 weETH withdrawal

An Etherscan transaction identified in the security alert shows the activity involving the first affected Safe.

The transaction records the burning of approximately 1,306.48 variableDebtEthWETH and the withdrawal of 1,306.48 weETH from Aave.

Transaction showing the withdrawal of 1,306.48 weETH
Transaction showing the withdrawal of 1,306.48 weETH | Source: Etherscan

Etherscan displayed the gross value of the collateral movement at approximately $3.88 million on the transaction page.

That figure should not be confused with the reported $305,000 loss. The Etherscan figure reflects the gross collateral movement recorded in that transaction, while the $305,000 figure is Defimon’s estimate of the overall loss.

Morpho flash loan used in transaction

The transaction also involved a WETH flash loan from Morpho, according to the Defimon alert.

Flash loans allow contracts to temporarily access liquidity within a single transaction, with the borrowed amount and applicable fee required to be returned or otherwise settled before the transaction completes. Aave documents flash loans as a standard V3 Pool feature.

In this case, the borrowed liquidity formed part of the transaction sequence involving the FlashLoopAdapter and affected Safe wallets.

The use of a flash loan does not by itself indicate a vulnerability in the protocol providing the liquidity.

Aave V3 was not the reported vulnerable component

The affected component was a custom FlashLoopAdapter contract built around Aave V3 leveraged-loop functionality.

Aave’s V3 documentation lists borrowing, repayment, withdrawals and flash loans among the protocol’s standard functions.

Based on the Defimon alert, the reported weakness instead involved the custom adapter’s access-control logic and its interaction with the affected Safe wallets.

The available information does not indicate that Aave V3’s core lending contracts were directly compromised.

September safe-wallet exploit also involved Aave V3

The incident follows a separate September 15 exploit involving an Ethereum Safe wallet holding a leveraged Aave V3 position.

In that case, approximately 2,900 rsETH worth around $7.8 million was drained after an attacker exploited a custom module attached to the Safe. An attacker-controlled Uniswap V4 hook converted the leveraged position into transferable rsETH, after which an MEV bot known as Yoink front-ran the exploit transaction and captured the funds.

Kelp DAO subsequently placed a temporary pause on the receiving address and said its core contracts and rsETH backing remained unaffected.

The September and October incidents used different attack paths, but both involved Safe wallets, leveraged Aave positions and custom smart-contract modules.

Custom modules add another attack surface

Safe wallets can authorize modules to perform specific operations on their behalf. These integrations can automate complex DeFi strategies, but their authorization and execution logic can introduce additional risks.

The recent Safe-related incidents show how vulnerabilities in custom integrations can affect assets held by a wallet without requiring a direct compromise of the underlying Aave contracts.

The FlashLoopAdapter investigation remains ongoing, and it is not yet clear whether additional wallets or contracts were affected.

Also Read: Two Men Arrested in San Jose Crypto-Targeted Home Invasion Attempt

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:AaveCrypto HackEthereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Smartphone displaying Starknet (STRK) price chart in front of Starknet office wall signage.
Starknet STRK Jumps 22.9% as Trading Volume Surges 
Smartphone displaying the Ondo Finance logo in front of Ondo wall signage.
Ondo Tokenized Value Hits $4B Across 10 Networks
Smartphone displaying the Aptos logo next to a magnifying glass showing the Aptos emblem in front of a red market chart.
Fact Check: Aptos Shutting Down the Chain in 6 Months?
Charles Hoskinson wearing glasses and a suit jacket seated in front of an IOHK logo backdrop.
Hoskinson Disputes Midnight’s $1.81 NIGHT Price Peak on CoinMarketCap
Bitcoin, Ethereum, and Solana physical tokens next to stacked ETF blocks in front of a red market chart.
Crypto ETFs Record $26.15M Outflow in Latest Week

Find Us on Socials

You may also like

Gala Games, Base, and Uniswap physical cryptocurrency tokens arranged in a row in front of a market chart.

GoldPesa’s GPXHooks Allegedly Drained for $114K in Base Exploit

On-chain detective ZachXBT avatar positioned between UPay and Xinbi logos representing illicit crypto card issuance investigation

UPay Opens Internal Investigation After ZachXBT Questions Sanctioned Xinbi Ties

BLAST Token Price Crashes Over 44% After Blast Announces Ethereum Layer 2 Shutdown

BLAST Token Price Crashes Over 44% After Blast Announces Ethereum Layer 2 Shutdown

Lloyds Bank signage with black horse logo on stone facade representing UK tokenized deposit and blockchain initiatives

71% of UK Financial Firms Expect Tokenization Shift: Lloyds 

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information