Attacker Exploited FlashLoopAdapter to Drain Ethereum Wallets

A vulnerability in authentication checks allowed unauthorized asset withdrawals from two Safe wallets.

Updated on Oct. 2, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a massive industrial steel lock mechanism and a disconnected bridge component representing a digital exploit.
An attacker drained $305,000 from two Safe wallets on the Ethereum blockchain after exploiting a critical authentication vulnerability in the FlashLoopAdapter contract. AI Illustration. Upload story photo >

Live Poll

Do you trust third-party apps connected to your digital wallet to keep your assets secure?

An attacker drained $305,000 from two Safe wallets on the Ethereum blockchain by exploiting a flaw in the FlashLoopAdapter contract. The incident occurred after the attacker bypassed authentication checks, ultimately retaining approximately 114.09 ETH after settling debts.

Why it matters

This exploit highlights critical risks in smart contract integration, specifically when adapter contracts fail to independently verify the legitimacy of the calling entity. The incident underscores the necessity for rigorous authentication standards in decentralized finance protocols.

The attacker withdrew 1,306 weETH and 6.4 weETH from the two wallets, utilizing a Morpho WETH flash loan to repay 1,335 WETH in Aave debt.

The players

Safe

A developer of smart contract-based wallets designed for multi-signature security on the Ethereum blockchain.

Aave

A decentralized finance protocol providing non-custodial liquidity markets for lending and borrowing crypto assets.

The details

The attacker deployed a malicious contract mimicking a legitimate Safe account, which returned a true status when queried by the FlashLoopAdapter. This deception allowed the attacker to successfully execute the execTransactionFromModule function, a method typically used to withdraw assets from Safe modules. The breach occurred because the adapter contract lacked an independent validation mechanism to confirm the identity of the calling contract.

Timeline

  1. 2026-10-01 15:08:57 UTC: The attack was detected by Defimon Alerts.

The Tech Race

This exploit demonstrates the ongoing tension between interoperability in decentralized finance and the security boundaries established by platforms like Safe. As protocols evolve, the race to implement zero-trust validation between modular components remains a primary challenge for smart contract security.

Users of modules interacting with the FlashLoopAdapter should verify the security parameters of their connected wallets immediately. While Aave v3 contracts remained unaffected, the incident serves as a reminder to audit the permissions granted to third-party modules.

The takeaway

Smart contract developers must ensure that adapter contracts perform independent authentication rather than relying on external statuses. Stakeholders should continue to monitor on-chain analytics platforms like Defimon for further reports regarding potential recovery efforts or subsequent contract patches.

Further reading

For more on the evolving security landscape of decentralized finance, visit Cybersecurity.

Live Poll

Do you trust third-party apps connected to your digital wallet to keep your assets secure?