FlashLoopAdapter exploit drains $305K from Aave V3 Safe module
On October 1, 2026, an attacker exploited a caller-authentication flaw in FlashLoopAdapter, a third-party module built on top of Aave V3, draining roughly $305,000–$310,000 from two Safe wallets. Aave V3's core contracts were unaffected, founder Stani Kulechov confirmed.
- Losses estimated at $305K–$310K across two Safe wallets owned by the same user
- Attacker used a Morpho WETH flash loan to repay ~1,335 WETH of Aave debt
- About 1,306.48 weETH was withdrawn from the first Safe and 6.4 weETH from the second
- Attacker's net profit reached roughly 114.09 ETH
Read next
Security