Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes

A custom Safe module used for Aave V3 leveraged positions was exploited through an access-control flaw, with collateral withdrawn from two affected wallets.

Written By Isha Chavda
Edited by Sujha Sundararajan
Published 1 hour ago
Make The Crypto Times preferred on GoogleGoogle
FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes

Key Highlights

  • A FlashLoopAdapter module linked to Aave V3 leveraged loops was exploited for an estimated $305,000 loss.
  • The incident involved an access-control flaw in the custom module.
  • Two Safe wallets were affected, with more than 1,300 weETH withdrawn from one of them.

A custom Ethereum module used to manage leveraged Aave V3 positions through Safe wallets was exploited on October 1, resulting in an estimated loss of about $305,000.

According to a security alert posted by Defimon Alerts on X, the affected component, identified as FlashLoopAdapter, is designed to open and close leveraged Aave positions for Safe wallets that have enabled the module. 

🚨 FlashLoopAdapter (@aave v3 loop Safe module) – Loss $305K (2026-10-01)

Network: Ethereum
Type: Access Control

FlashLoopAdapter is a Safe module that opens/closes Aave v3 leveraged loops for the Safes that enable it. open()/close() trust any msg.sender that answers… pic.twitter.com/uFwSQ69Lpv

— Defimon Alerts (@DefimonAlerts) October 1, 2026

According to the alert, an attacker-controlled contract was able to pass the module’s access-control checks and use its execution path to move collateral from two affected Safes.

The reported weakness was in the custom FlashLoopAdapter contract built around Aave V3, rather than in Aave V3’s core lending contracts.

FlashLoopAdapter module exploited

FlashLoopAdapter provides an additional execution layer for leveraged Aave positions held through participating Safe wallets.

According to Defimon, its authorization logic allowed an attacker-controlled contract to satisfy the conditions required to execute operations.

The attacker then used the module’s execution path to interact with the affected Safes and withdraw collateral.

Two Safe wallets were affected

The security alert identified two affected Safe wallets.

In the first case, the transaction involved repayment of approximately 1,335 WETH of Aave debt, followed by the withdrawal of approximately 1,306.48 weETH from the Safe.

A second Safe lost approximately 6.4 weETH.

The attacker subsequently converted part of the withdrawn assets and retained approximately 114.1 ETH, according to the alert.

Defimon estimated the overall loss at approximately $305,000.

Etherscan shows 1,306.48 weETH withdrawal

An Etherscan transaction identified in the security alert shows the activity involving the first affected Safe.

The transaction records the burning of approximately 1,306.48 variableDebtEthWETH and the withdrawal of 1,306.48 weETH from Aave.

Transaction showing the withdrawal of 1,306.48 weETH

Transaction showing the withdrawal of 1,306.48 weETH | Source: Etherscan

Etherscan displayed the gross value of the collateral movement at approximately $3.88 million on the transaction page.

That figure should not be confused with the reported $305,000 loss. The Etherscan figure reflects the gross collateral movement recorded in that transaction, while the $305,000 figure is Defimon’s estimate of the overall loss.

Morpho flash loan used in transaction

The transaction also involved a WETH flash loan from Morpho, according to the Defimon alert.

Flash loans allow contracts to temporarily access liquidity within a single transaction, with the borrowed amount and applicable fee required to be returned or otherwise settled before the transaction completes. Aave documents flash loans as a standard V3 Pool feature.

In this case, the borrowed liquidity formed part of the transaction sequence involving the FlashLoopAdapter and affected Safe wallets.

The use of a flash loan does not by itself indicate a vulnerability in the protocol providing the liquidity.

Aave V3 was not the reported vulnerable component

The affected component was a custom FlashLoopAdapter contract built around Aave V3 leveraged-loop functionality.

Aave’s V3 documentation lists borrowing, repayment, withdrawals and flash loans among the protocol’s standard functions.

Based on the Defimon alert, the reported weakness instead involved the custom adapter’s access-control logic and its interaction with the affected Safe wallets.

The available information does not indicate that Aave V3’s core lending contracts were directly compromised.

September safe-wallet exploit also involved Aave V3

The incident follows a separate September 15 exploit involving an Ethereum Safe wallet holding a leveraged Aave V3 position.

In that case, approximately 2,900 rsETH worth around $7.8 million was drained after an attacker exploited a custom module attached to the Safe. An attacker-controlled Uniswap V4 hook converted the leveraged position into transferable rsETH, after which an MEV bot known as Yoink front-ran the exploit transaction and captured the funds.

Kelp DAO subsequently placed a temporary pause on the receiving address and said its core contracts and rsETH backing remained unaffected.

The September and October incidents used different attack paths, but both involved Safe wallets, leveraged Aave positions and custom smart-contract modules.

Custom modules add another attack surface

Safe wallets can authorize modules to perform specific operations on their behalf. These integrations can automate complex DeFi strategies, but their authorization and execution logic can introduce additional risks.

The recent Safe-related incidents show how vulnerabilities in custom integrations can affect assets held by a wallet without requiring a direct compromise of the underlying Aave contracts.

The FlashLoopAdapter investigation remains ongoing, and it is not yet clear whether additional wallets or contracts were affected.

Also Read: Two Men Arrested in San Jose Crypto-Targeted Home Invasion Attempt

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:AaveEthereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

SEC Proposes Tailored Crypto Custody Rules for Advisers and Funds
SEC Proposes Tailored Crypto Custody Rules for Advisers and Funds
Galaxy Finds 69% of Polymarket Retail Accounts Lost Money
Galaxy Finds 69% of Polymarket Retail Accounts Lost Money
Ripple Launches RLUSD Insurance Pilot for Ugandan Farmers
Ripple Launches RLUSD Insurance Pilot for Ugandan Farmers
Shielded Labs Launches Epoch to Develop Post-Quantum Cryptography for Zcash
Shielded Labs Launches Epoch to Develop Post-Quantum Cryptography for Zcash
Bitcoin Leads Crypto ETF Inflows as September Ends With Outflows
Bitcoin Leads Crypto ETF Inflows as September Ends With Outflows

Find Us on Socials

You may also like

Chainlink Named Oracle for Open Standard’s OUSD Stablecoin

Chainlink Named Oracle for Open Standard’s OUSD Stablecoin

Physical gold Bitcoin coins in front of a brightly lit white and yellow Bybit logo on a dark background.

Bybit Users Hold More BTC and ETH as USDT Balances Fall 11%

Binance’s EU Comeback Draws Regulatory Questions Over MiCA: FT

Binance’s EU Comeback Draws Regulatory Questions Over MiCA: FT

Physical Bitcoin and Ethereum coins with the Singapore flag and Marina Bay Sands skyline in the background.

Singapore Crypto Activity Rises 55% as Institutional Activity Surges 94%

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information