FlashLoopAdapter (Aave v3 Safe module) exploited via access control flaw; attackers drained $305K from two Safes using flash loans and module impersonation.
Security & Exploits ·
FlashLoopAdapter, a Safe module designed to manage Aave v3 leveraged positions, suffered an exploit that drained approximately $305,000 across two victim Safes on October 1, 2026. The vulnerability lay in flawed access control: the module's open() and close() functions trusted any caller claiming to be an enabled module, allowing an attacker to impersonate a Safe. By deploying a contract that also served as a flash loan provider, the attacker bypassed the callback's validation checks and exploited the _swap() function's reliance on caller-supplied router addresses and call data.
The attacker leveraged a Morpho WETH flash loan to repay debt in the first victim Safe (0xcfed…), then used the module's privileges to withdraw 1,306 weETH in collateral and route it to their address. From a second Safe (0xe3b2…) controlled by the same owner, they extracted 6.4 weETH, swapped it, and retained 114.1 ETH. The exploit demonstrates how custom modules built atop Aave v3 can introduce systemic risks; Aave v3 itself remained unaffected. The vulnerable module contract and related transaction details are publicly visible on-chain, though the underlying root cause—why module verification failed—remains a point of scrutiny for Safe ecosystem security.