TLDR
- A custom module called FlashLoopAdapter, used for Aave V3 leveraged positions, was exploited on October 1.
- The exploit relied on an access-control flaw, not a flaw in Aave’s core lending contracts.
- Two Safe wallets were affected, with more than 1,300 weETH taken from one of them.
- The attacker used a WETH flash loan from Morpho as part of the attack sequence.
- The estimated loss is about $305,000 to $310,000, with roughly 114 ETH recovered by the attacker.
A custom Ethereum module used to manage leveraged Aave V3 positions was exploited on October 1. The attack led to an estimated loss of about $305,000.
🚨 FlashLoopAdapter (@aave v3 loop Safe module) – Loss $305K (2026-10-01)
Network: Ethereum
Type: Access ControlFlashLoopAdapter is a Safe module that opens/closes Aave v3 leveraged loops for the Safes that enable it. open()/close() trust any msg.sender that answers… pic.twitter.com/uFwSQ69Lpv
— Defimon Alerts (@DefimonAlerts) October 1, 2026
The affected module is called FlashLoopAdapter. It is built to open and close leveraged Aave positions for Safe wallets that have the module enabled.
Security firm Defimon Alerts posted details of the incident on X. The firm said an attacker-controlled contract was able to pass the module’s access checks.
How The Exploit Worked
Once the attacker passed those checks, they used the module’s execution path to interact with two Safe wallets. This allowed them to move collateral out of the wallets.
NEW: SlowMist flagged that a Safe module used for Aave v3 loops was exploited for roughly 114.09 ETH ($310,000).
The attacker reportedly forged Safe authentication and repaid about 1,300 WETH in debt to unlock collateral before draining assets from two multisigs. pic.twitter.com/SSvR0qEOLD
— The Block (@TheBlockCo) October 2, 2026
In the first case, the attacker repaid about 1,335 WETH of Aave debt. They then withdrew about 1,306.48 weETH from the Safe wallet.
A second Safe wallet lost about 6.4 weETH in the same incident.
After the withdrawal, the attacker converted part of the assets. They kept about 114.1 ETH, according to Defimon.
An Etherscan transaction tied to the first Safe wallet showed the burning of about 1,306.48 variableDebtEthWETH tokens. It also showed the withdrawal of a matching amount of weETH.
Etherscan listed the gross value of that transaction at about $3.88 million. That number reflects the total collateral moved, not the final loss figure.
The $305,000 estimate from Defimon reflects the actual loss after the attacker’s assets were accounted for.
Flash Loan Used In The Attack
The transaction also involved a flash loan. The attacker borrowed WETH from Morpho as part of the attack sequence.
Flash loans let a contract borrow funds for a single transaction. The loan must be repaid, with any fee, before the transaction finishes.
Aave lists flash loans as a standard feature of its V3 lending pool. Using a flash loan does not on its own point to a flaw in the lender providing it.
The reported weakness was in the custom FlashLoopAdapter contract, not in Aave’s core lending code. Aave’s documentation lists borrowing, repayment, withdrawals and flash loans as standard V3 functions.
This is not the first incident of its kind this year. On September 15, a separate Safe wallet holding a leveraged Aave V3 position was drained of about 2,900 rsETH, worth around $7.8 million at the time.
In that case, an attacker used a Uniswap V4 hook to convert the position into transferable rsETH. A bot called Yoink then front-ran the attacker’s own transaction and took the funds instead.
Kelp DAO, the protocol behind rsETH, paused the receiving address after that incident. It said its core contracts and the backing for rsETH were not affected.
Security firm SlowMist also reported on the October 1 incident, giving a loss estimate of about $310,000 and 114.09 ETH. SlowMist said the attacker used a forged Safe wallet to bypass authentication, then used arbitrary transaction data to access the funds.
The FlashLoopAdapter investigation is still open. It is not yet confirmed whether any other wallets or contracts were affected.







