Key Highlights
- A FlashLoopAdapter module linked to Aave V3 leveraged loops was exploited for an estimated $305,000 loss.
- The incident involved an access-control flaw in the custom module.
- Two Safe wallets were affected, with more than 1,300 weETH withdrawn from one of them.
A custom Ethereum module used to manage leveraged Aave V3 positions through Safe wallets was exploited on October 1, resulting in an estimated loss of about $305,000.
According to a security alert posted by Defimon Alerts on X, the affected component, identified as FlashLoopAdapter, is designed to open and close leveraged Aave positions for Safe wallets that have enabled the module.
According to the alert, an attacker-controlled contract was able to pass the module’s access-control checks and use its execution path to move collateral from two affected Safes.
The reported weakness was in the custom FlashLoopAdapter contract built around Aave V3, rather than in Aave V3’s core lending contracts.
FlashLoopAdapter module exploited
FlashLoopAdapter provides an additional execution layer for leveraged Aave positions held through participating Safe wallets.
According to Defimon, its authorization logic allowed an attacker-controlled contract to satisfy the conditions required to execute operations.
The attacker then used the module’s execution path to interact with the affected Safes and withdraw collateral.
Two Safe wallets were affected
The security alert identified two affected Safe wallets.
In the first case, the transaction involved repayment of approximately 1,335 WETH of Aave debt, followed by the withdrawal of approximately 1,306.48 weETH from the Safe.
A second Safe lost approximately 6.4 weETH.
The attacker subsequently converted part of the withdrawn assets and retained approximately 114.1 ETH, according to the alert.
Defimon estimated the overall loss at approximately $305,000.
Etherscan shows 1,306.48 weETH withdrawal
An Etherscan transaction identified in the security alert shows the activity involving the first affected Safe.
The transaction records the burning of approximately 1,306.48 variableDebtEthWETH and the withdrawal of 1,306.48 weETH from Aave.

Transaction showing the withdrawal of 1,306.48 weETH | Source: Etherscan
Etherscan displayed the gross value of the collateral movement at approximately $3.88 million on the transaction page.
That figure should not be confused with the reported $305,000 loss. The Etherscan figure reflects the gross collateral movement recorded in that transaction, while the $305,000 figure is Defimon’s estimate of the overall loss.
Morpho flash loan used in transaction
The transaction also involved a WETH flash loan from Morpho, according to the Defimon alert.
Flash loans allow contracts to temporarily access liquidity within a single transaction, with the borrowed amount and applicable fee required to be returned or otherwise settled before the transaction completes. Aave documents flash loans as a standard V3 Pool feature.
In this case, the borrowed liquidity formed part of the transaction sequence involving the FlashLoopAdapter and affected Safe wallets.
The use of a flash loan does not by itself indicate a vulnerability in the protocol providing the liquidity.
Aave V3 was not the reported vulnerable component
The affected component was a custom FlashLoopAdapter contract built around Aave V3 leveraged-loop functionality.
Aave’s V3 documentation lists borrowing, repayment, withdrawals and flash loans among the protocol’s standard functions.
Based on the Defimon alert, the reported weakness instead involved the custom adapter’s access-control logic and its interaction with the affected Safe wallets.
The available information does not indicate that Aave V3’s core lending contracts were directly compromised.
September safe-wallet exploit also involved Aave V3
The incident follows a separate September 15 exploit involving an Ethereum Safe wallet holding a leveraged Aave V3 position.
In that case, approximately 2,900 rsETH worth around $7.8 million was drained after an attacker exploited a custom module attached to the Safe. An attacker-controlled Uniswap V4 hook converted the leveraged position into transferable rsETH, after which an MEV bot known as Yoink front-ran the exploit transaction and captured the funds.
Kelp DAO subsequently placed a temporary pause on the receiving address and said its core contracts and rsETH backing remained unaffected.
The September and October incidents used different attack paths, but both involved Safe wallets, leveraged Aave positions and custom smart-contract modules.
Custom modules add another attack surface
Safe wallets can authorize modules to perform specific operations on their behalf. These integrations can automate complex DeFi strategies, but their authorization and execution logic can introduce additional risks.
The recent Safe-related incidents show how vulnerabilities in custom integrations can affect assets held by a wallet without requiring a direct compromise of the underlying Aave contracts.
The FlashLoopAdapter investigation remains ongoing, and it is not yet clear whether additional wallets or contracts were affected.
Also Read: Two Men Arrested in San Jose Crypto-Targeted Home Invasion Attempt
