Skip to main content
AVOID.NET

FlashLoopAdapter (Aave v3 Safe Module Exploit)

avoid.net/flashloopadapter-aave-v3-safe-module-exploit→10/100·82% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2Sobjz…kwts
last updated 2026-10-02

Summary

FlashLoopAdapter is a third-party Safe module designed to automate the opening and closing of leveraged positions on Aave v3. On October 1, 2026, an attacker exploited a critical access control vulnerability in the module's open() and close() functions, draining approximately 114.09 ETH (estimated at $305,000–$310,000) from two Safe multisig wallets on Ethereum. Neither Aave v3 nor Safe's core infrastructure was compromised; the flaw resided entirely within the third-party adapter.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about FlashLoopAdapter (Aave v3 Safe Module Exploit)?

Timeline(5 events)

1 October 2026

Attack executed at approximately 15:08:57 UTC. Attacker (0x42c2633438609881c8fBAb82414eb9A0c45F9353) deployed a fake Safe contract, obtained a Morpho WETH flash loan, repaid approximately 1,335 WETH of Aave v3 debt across two victim Safes, and withdrew approximately 1,306.48 weETH and 6.4 weETH, retaining ~114.09 ETH as net profit. Both victim Safes disabled the FlashLoopAdapter module after the attack.

crypto.news / SlowMist

1 October 2026

SlowMist issues public alert identifying the access control vulnerability and publishing attacker and contract addresses.

mpost.io

2 October 2026

Aave founder Stani Kulechov publicly clarifies that Aave v3 core contracts were unaffected and describes the FlashLoopAdapter as a third-party external adapter.

KuCoin News

2 October 2026

Wallet owner aavechan.eth sends on-chain message to attacker offering a 10% whitehat bounty: attacker may retain 11.41 ETH and must return 102.69 ETH before October 3 at 18:00 UTC.

Blockfence / Crypto Briefing

2 October 2026

Multiple crypto news outlets publish full coverage. Incident is categorized as a third-party module exploit, not an Aave v3 or Safe infrastructure breach.

CryptoTimes / Blockonomi / crypto.news / Crypto Briefing
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 8 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 10/2/2026, 5:05:28 PM

last updated: 10/2/2026, 6:10:03 PM

avoid.net — verified advice for a post-truth world