Skip to main content
AVOID.NET

FlashLoopAdapter

avoid.net/flashloopadapter→12/100·75% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·gP8kms…BG29
last updated 2026-10-04

Summary

FlashLoopAdapter is a third-party Safe (Gnosis Safe) module used to open and close leveraged positions on Aave V3. It is not an Aave or Safe product. On October 1, 2026, an access-control flaw in the module was exploited, draining roughly 114 ETH (about $305,000) from two Safe wallets that had enabled it. A detailed incident writeup exists at /flashloopadapter-aave-v3-safe-module-exploit; this page covers FlashLoopAdapter as an entity rather than restating that page's findings or score.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about FlashLoopAdapter?

Timeline(4 events)

1 October 2026

Attacker exploits an access-control flaw in FlashLoopAdapter, using a Morpho flash loan to repay Aave debt on two Safe wallets and withdraw their freed collateral, netting roughly 114 ETH (~$305K).

Cryptonomist

October 2026

Security monitoring service Defimon Alerts and security firm SlowMist identify and publicize the exploit and its root cause in FlashLoopAdapter's authentication logic.

crypto.news / KuCoin news (SlowMist analysis)

October 2026

Aave founder Stani Kulechov states publicly that FlashLoopAdapter is a third-party adapter built on top of Aave and that the exploit had no effect on Aave V3's core protocol.

Crypto Economy

October 2026

A proof-of-concept reproducing the exploit, attributing it to broken self-attestation and an unconstrained external call in FlashLoopAdapter, is submitted to the DeFiHackLabs public repository.

GitHub - SunWeb3Sec/DeFiHackLabs PR #1287
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 9 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 10/4/2026, 12:12:04 PM

last updated: 10/4/2026, 12:12:11 PM

avoid.net — verified advice for a post-truth world