Skip to main content
AVOID.NET

Audit log

Every state-changing event for FlashLoopAdapter (Aave v3 Safe Module Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-02 17:05:37Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 452,672,540
    sig
    2SobjzeFZb1k…9KzEkwtsexplorer ↗
    hash
    ELC6Ls4mDGzi…JSUWhShAsha256 → base58
    verifying row…full verify ↗
    canonical bytes (18486 B) ▸
    {"actor":"system:backfill","investigation_id":"b4f97d31-3bf4-4118-aae4-ecc0c1826a1e","kind":"publish","page_slug":"flashloopadapter-aave-v3-safe-module-exploit","published_at":"2026-10-02T17:05:37.012Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"FlashLoopAdapter (Aave v3 Safe Module Exploit)","sections":[{"content":"On October 1, 2026, at approximately 15:08:57 UTC, an attacker exploited a critical access control vulnerability in FlashLoopAdapter, a custom Safe module that enables users to open and close leveraged positions on Aave v3. The exploit drained approximately 114.09 ETH from two Safe multisig wallets, with total victim losses estimated between $305,000 and $310,000 depending on the ETH price at time of execution. Both affected Safe wallets are reported by multiple sources to have belonged to the same owner, identified on-chain by the ENS name aavechan.eth. The entire attack was executed in a single transaction. Blockchain security firm SlowMist first publicly identified and reported the vulnerability. Aave founder Stani Kulechov publicly clarified that the affected contract was a third-party external adapter and had zero effect on Aave v3.","heading":"Incident Overview","severity":"high","sources":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"Aave Founder Clarifies That v3 Is Not Affected by Recent Attack on Third-Party Module — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"}]},{"content":"The vulnerability was an access control flaw in the FlashLoopAdapter contract's open() and close() functions. Rather than independently verifying the caller's identity, these functions checked only whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true. Because this check relied entirely on the calling contract's own response, an attacker could deploy a fake Safe contract programmed to always return true when queried, bypassing authentication.\n\nOnce the fake Safe passed authentication, the attacker abused the module's _swap() function. This function executed a raw call to a caller-supplied swap router using fully attacker-controlled calldata. The attacker set the router address to a victim Safe wallet and the calldata to execTransactionFromModule — a Safe function that permits an enabled module to execute transactions on the Safe's behalf. Because FlashLoopAdapter was already legitimately enabled as a module on the victim Safes, the adapter's existing permissions were effectively turned into a remote-control mechanism over the victims' assets.\n\nThe root cause is a classic reentrancy-adjacent pattern: caller-controlled input to a privileged function with insufficient identity validation. The vulnerable contract address is reported as 0x16bb8b912da187870c23ec6756bb3fad061283d8.","heading":"Technical Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"}]},{"content":"The attack was executed in a single Ethereum transaction on October 1, 2026. The attacker (wallet address 0x42c2633438609881c8fBAb82414eb9A0c45F9353) carried out the following steps:\n\n1. Obtained a WETH flash loan from Morpho protocol.\n2. Used the borrowed funds to repay approximately 1,335 WETH of outstanding Aave v3 debt held by the two victim Safe wallets. Repaying this debt freed the collateral backing it.\n3. Exploited the access control flaw to call execTransactionFromModule on the victim Safes, withdrawing approximately 1,306.48 weETH from the first Safe (0xcfedf95a3653a128dfc2e4288758a1a1850d169f) and 6.4 weETH from the second Safe (0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520).\n4. Repaid the Morpho flash loan from the withdrawn collateral.\n5. Retained approximately 114.09 ETH as net profit, worth approximately $305,000–$310,000 at the time.\n\nThe two on-chain transactions referenced in reporting include hash 0x75328f916b1a0878724d364da5eb12b255160b894cb36c63ed5d718efc616fc4 for the primary Safe withdrawal.","heading":"Attack Execution and Financial Impact","severity":"critical","sources":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"},{"credibility":2,"name":"Aave v3 Loop Safe Module Hacked, 114 ETH Stolen — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-v3-loop-safe-module-hacked-114-eth-stolen"},{"credibility":2,"name":"Aave Hack: FlashLoopAdapter Hits Two Safe Wallets — CryptoTimes (loop module article)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/aave-v3-loop-module-hacked-for-114-eth-aaves-pools-not-affected/"}]},{"content":"Multiple security analysts and the affected parties confirmed that neither Aave v3's core smart contracts nor Safe's core multisig infrastructure were exploited. The flaw existed exclusively within the FlashLoopAdapter third-party module. Aave founder Stani Kulechov stated publicly that the affected contract was 'a third party external adapter built on top of Aave' and had 'zero effect on Aave v3.' The Aave v3 lending pools continued to operate normally throughout the incident. Safe's core execution logic was not bypassed; the attacker abused the module permission system as designed, exploiting only the adapter's failure to validate caller identity prior to granting those permissions effect.\n\nThis distinction is significant for risk assessment: the vulnerability category is third-party integration risk, not a protocol-level flaw in Aave or Safe.","heading":"Scope: Aave v3 and Safe Infrastructure Not Compromised","severity":"medium","sources":[{"credibility":2,"name":"Aave Founder Clarifies That v3 Is Not Affected by Recent Attack on Third-Party Module — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"},{"credibility":2,"name":"Aave v3 Unaffected After Third Party Adapter Hack Hits Safe Wallets — Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-v3-unaffected-after-third-party-adapter-hack-hits-safe-wallets"},{"credibility":2,"name":"Aave founder: The Loop Safe Module is a third-party adapter — ChainCatcher","type":"news_article","url":"https://www.chaincatcher.com/en/article/2293674"}]},{"content":"Following the exploit, both victim Safe wallets disabled the vulnerable FlashLoopAdapter module to prevent further losses. The wallet owner, identified on-chain by the ENS name aavechan.eth, sent an on-chain message to the attacker's address offering a 10% whitehat bounty. Under the terms offered, the attacker could retain 11.41 ETH and was asked to return 102.69 ETH before October 3, 2026 at 18:00 UTC, with the offer stated to expire at that deadline.\n\nAs of the time of this investigation (October 2, 2026), no public reporting confirms whether the attacker accepted, declined, or ignored the bounty offer. The attacker's identity remains unknown. No law enforcement referral or on-chain tracing to a known entity has been publicly reported. No formal post-mortem from the module's developer has been published, and the module's creator has not been publicly identified in available sources.","heading":"Post-Incident Response and Recovery Efforts","severity":"high","sources":[{"credibility":2,"name":"FlashLoopAdapter Flaw Drains $305K From Aave-Linked Safe Wallets — Blockfence","type":"news_article","url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"Aave-Linked Module Bypassed Safe Wallet Security — DailyCoin","type":"news_article","url":"https://dailycoin.com/aave-safe-wallet-exploit"}]},{"content":"Available public sources do not identify the developer or development team responsible for the FlashLoopAdapter contract. No prior security audit of the FlashLoopAdapter contract has been referenced in any reporting. No GitHub repository, documentation site, or official project page for the module has been identified in public sources at the time of this investigation. The absence of disclosed authorship and audit history are themselves risk signals for third-party DeFi tooling. One report noted this incident resembles a pattern of third-party module vulnerabilities built on top of Aave v3, suggesting the exploit may not be isolated.","heading":"Audit and Development History","severity":"high","sources":[{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K from Aave-Linked Safe Wallets — Bitbase","type":"news_article","url":"https://www.bitbase.com/news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets"},{"credibility":2,"name":"FlashLoopAdapter Flaw Drains $305K From Aave-Linked Safe Wallets — Blockfence","type":"news_article","url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"}]},{"content":"Blockchain security firm SlowMist was the primary source of technical analysis for this incident, issuing an alert identifying the access control vulnerability in the FlashLoopAdapter's open() and close() functions. SlowMist confirmed the attacker address as 0x42c2633438609881c8fBAb82414eb9A0c45F9353 and the vulnerable contract address as 0x16bb8b912da187870c23ec6756bb3fad061283d8. Security monitoring platform Defimon Alerts and security firm ExVul are also cited by multiple outlets as having identified the vulnerability post-incident. No pre-incident disclosure or responsible disclosure process has been reported.","heading":"Security Firm Analysis","severity":"high","sources":[{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Attacked, 114 ETH Stolen — PANews","type":"news_article","url":"https://panews.io/articles/01a0faa1-55ab-77fc-b694-4000ec063ee6"},{"credibility":3,"name":"BSCN on X: Aave V3 Safe Module Hit By Access Control Exploit","type":"social_media","url":"https://x.com/BSCNews/status/2105892590315028553"}]}],"sources_used":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"},{"credibility":2,"name":"Aave v3 Loop Module Hacked for 114 ETH. Aave's Pools Were Used, Not Broken — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/aave-v3-loop-module-hacked-for-114-eth-aaves-pools-not-affected/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"Aave Founder Clarifies That v3 Is Not Affected by Recent Attack on Third-Party Module — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"},{"credibility":2,"name":"Aave v3 Loop Safe Module Hacked, 114 ETH Stolen — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-v3-loop-safe-module-hacked-114-eth-stolen"},{"credibility":2,"name":"Aave v3 Unaffected After Third Party Adapter Hack Hits Safe Wallets — Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-v3-unaffected-after-third-party-adapter-hack-hits-safe-wallets"},{"credibility":2,"name":"FlashLoopAdapter Exploit Results in $305K Loss from Ethereum Safe Wallets — Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-linked-safe-wallet-module-exploited-over-300000-drained-from-two-wallets-pnr-da8312b502859cda1512ea4e"},{"credibility":2,"name":"FlashLoopAdapter Flaw Drains $305K From Aave-Linked Safe Wallets — Blockfence","type":"news_article","url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave-Linked Module Bypassed Safe Wallet Security — DailyCoin","type":"news_article","url":"https://dailycoin.com/aave-safe-wallet-exploit"},{"credibility":2,"name":"Aave V3 Exploit Targets FlashLoopAdapter Draining $300K — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/10/02/aave-v3-exploit-flashloopadapter/"},{"credibility":2,"name":"Aave-Linked Safe Wallets Drained of Up to $310K in FlashLoopAdapter Exploit — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-linked-safe-wallets-drained-of-up-to-310k-in-flashloopadapter-exploit"},{"credibility":2,"name":"Aave founder: The Loop Safe Module is a third-party adapter — ChainCatcher","type":"news_article","url":"https://www.chaincatcher.com/en/article/2293674"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Attacked, 114 ETH Stolen — PANews","type":"news_article","url":"https://panews.io/articles/01a0faa1-55ab-77fc-b694-4000ec063ee6"},{"credibility":3,"name":"BSCN on X: Aave V3 Safe Module Hit By Access Control Exploit","type":"social_media","url":"https://x.com/BSCNews/status/2105892590315028553"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K from Aave-Linked Safe Wallets — Bitbase","type":"news_article","url":"https://www.bitbase.com/news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets"},{"credibility":2,"name":"Aave V3 Loop Module Exploit Drains About 114 ETH — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/technology/26274"}],"summary":"FlashLoopAdapter is a third-party Safe module designed to automate the opening and closing of leveraged positions on Aave v3. On October 1, 2026, an attacker exploited a critical access control vulnerability in the module's open() and close() functions, draining approximately 114.09 ETH (estimated at $305,000–$310,000) from two Safe multisig wallets on Ethereum. Neither Aave v3 nor Safe's core infrastructure was compromised; the flaw resided entirely within the third-party adapter.","timeline":[{"date":"2026-10-01","event":"Attack executed at approximately 15:08:57 UTC. Attacker (0x42c2633438609881c8fBAb82414eb9A0c45F9353) deployed a fake Safe contract, obtained a Morpho WETH flash loan, repaid approximately 1,335 WETH of Aave v3 debt across two victim Safes, and withdrew approximately 1,306.48 weETH and 6.4 weETH, retaining ~114.09 ETH as net profit. Both victim Safes disabled the FlashLoopAdapter module after the attack.","source":"crypto.news / SlowMist","source_url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"date":"2026-10-01","event":"SlowMist issues public alert identifying the access control vulnerability and publishing attacker and contract addresses.","source":"mpost.io","source_url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"date":"2026-10-02","event":"Aave founder Stani Kulechov publicly clarifies that Aave v3 core contracts were unaffected and describes the FlashLoopAdapter as a third-party external adapter.","source":"KuCoin News","source_url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"},{"date":"2026-10-02","event":"Wallet owner aavechan.eth sends on-chain message to attacker offering a 10% whitehat bounty: attacker may retain 11.41 ETH and must return 102.69 ETH before October 3 at 18:00 UTC.","source":"Blockfence / Crypto Briefing","source_url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"},{"date":"2026-10-02","event":"Multiple crypto news outlets publish full coverage. Incident is categorized as a third-party module exploit, not an Aave v3 or Safe infrastructure breach.","source":"CryptoTimes / Blockonomi / crypto.news / Crypto Briefing","source_url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 561ee443-276b-4e72-8b8f-2819835c0df6
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.