FlashLoopAdapter (Aave v3 Safe Module Exploit)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2Sobjz…kwtsSummary
FlashLoopAdapter is a third-party Safe module designed to automate the opening and closing of leveraged positions on Aave v3. On October 1, 2026, an attacker exploited a critical access control vulnerability in the module's open() and close() functions, draining approximately 114.09 ETH (estimated at $305,000–$310,000) from two Safe multisig wallets on Ethereum. Neither Aave v3 nor Safe's core infrastructure was compromised; the flaw resided entirely within the third-party adapter.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(5 events)
1 October 2026
Attack executed at approximately 15:08:57 UTC. Attacker (0x42c2633438609881c8fBAb82414eb9A0c45F9353) deployed a fake Safe contract, obtained a Morpho WETH flash loan, repaid approximately 1,335 WETH of Aave v3 debt across two victim Safes, and withdrew approximately 1,306.48 weETH and 6.4 weETH, retaining ~114.09 ETH as net profit. Both victim Safes disabled the FlashLoopAdapter module after the attack.
crypto.news / SlowMist1 October 2026
SlowMist issues public alert identifying the access control vulnerability and publishing attacker and contract addresses.
mpost.io2 October 2026
Aave founder Stani Kulechov publicly clarifies that Aave v3 core contracts were unaffected and describes the FlashLoopAdapter as a third-party external adapter.
KuCoin News2 October 2026
Wallet owner aavechan.eth sends on-chain message to attacker offering a 10% whitehat bounty: attacker may retain 11.41 ETH and must return 102.69 ETH before October 3 at 18:00 UTC.
Blockfence / Crypto Briefing2 October 2026
Multiple crypto news outlets publish full coverage. Incident is categorized as a third-party module exploit, not an Aave v3 or Safe infrastructure breach.
CryptoTimes / Blockonomi / crypto.news / Crypto BriefingDecision Log
- hash: ELC6Ls4mDGzis5csqhaj13EvMi2sFQCft24yJSUWhShA
This investigation is cryptographically anchored to the Solana blockchain (1 event). 8 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 10/2/2026, 5:05:28 PM
last updated: 10/2/2026, 6:10:03 PM
avoid.net — verified advice for a post-truth world