A flaw in the access controls of a FlashLoopAdapter contract allowed an attacker to drain roughly $305,000 from two Safe wallets on Ethereum, according to findings shared by blockchain security firm SlowMist.

The incident did not stem from the core Aave v3 protocol. Aave founder Stani Kulechov said the affected software was a third-party adapter built on top of Aave and that the event had zero effect on Aave v3 itself.

Authentication check could be spoofed

SlowMist said the weakness was in how the FlashLoopAdapter verified who was allowed to call key functions. The adapter is designed as a Safe module that can open and close leveraged Aave v3 loop positions for wallets that have enabled it.

According to the security analysis, the contract’s open() and close() access control relied on the check ISafe(msg.sender).isModuleEnabled(address(this)). That verification could be spoofed by a fake Safe, allowing an attacker to pass checks that were meant to restrict access to approved wallets only.

Once that hurdle was cleared, the attacker was able to reach functionality that should have been limited to Safes that had actually enabled the module. SlowMist said this let the attacker forge Safe authentication and manipulate positions tied to the affected wallets.

How the exploit unfolded

The attacker then controlled the adapter’s router and calldata and directed the module toward the victim Safes, according to the report. Defimon Alerts first detected the attack and also noted that Aave v3 itself was not the compromised component.

To execute the theft, the attacker used a flash loan from Morpho. The borrowed funds were used to repay roughly 1,335 WETH of Aave debt on the larger of the two impacted wallets, which in turn made it possible to pull out the associated collateral.

SlowMist said the attacker withdrew about 1,306 weETH from the first Safe and another 6.4 weETH from the second. After swapping part of the assets, the exploiter was left with around 114.09 ETH, or about $305,000 at the time.

Impact limited to an external adapter

The facts published so far point to a custom contract built around Aave rather than a failure in Aave v3’s core contracts. That distinction was emphasized both by SlowMist and by Kulechov after the exploit was identified.

FlashLoopAdapter appears to have inherited risk from the same module permissions that let it manage Aave loop positions on behalf of Safe wallets. In this case, those permissions became part of the attack path once the authentication check could be imitated by a malicious contract.

As a result, the losses were confined to the wallets using the vulnerable adapter logic, while the underlying Aave v3 protocol was reported to be unaffected.

What is confirmed so far

The confirmed picture remains narrow but important: two Safe wallets on Ethereum were drained through an access-control flaw in a third-party FlashLoopAdapter, and the attacker ultimately kept around 114.1 ETH.

No further impact to Aave v3 was identified in the source reporting. The clearest next step is continued review of external modules and adapters that sit on top of major lending protocols, especially where Safe module permissions and caller verification are involved.

Source: crypto.news