Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
452672540
Off-chain at
2026-10-02T17:05:37.128Z
Anchored at
2026-10-02T17:05:53.747Z
Block time
—

Independent verification

1. Database (off-chain)
ELC6Ls4mDGzis5csqhaj13EvMi2sFQCft24yJSUWhShA
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (18486 chars)
{"actor":"system:backfill","investigation_id":"b4f97d31-3bf4-4118-aae4-ecc0c1826a1e","kind":"publish","page_slug":"flashloopadapter-aave-v3-safe-module-exploit","published_at":"2026-10-02T17:05:37.012Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"FlashLoopAdapter (Aave v3 Safe Module Exploit)","sections":[{"content":"On October 1, 2026, at approximately 15:08:57 UTC, an attacker exploited a critical access control vulnerability in FlashLoopAdapter, a custom Safe module that enables users to open and close leveraged positions on Aave v3. The exploit drained approximately 114.09 ETH from two Safe multisig wallets, with total victim losses estimated between $305,000 and $310,000 depending on the ETH price at time of execution. Both affected Safe wallets are reported by multiple sources to have belonged to the same owner, identified on-chain by the ENS name aavechan.eth. The entire attack was executed in a single transaction. Blockchain security firm SlowMist first publicly identified and reported the vulnerability. Aave founder Stani Kulechov publicly clarified that the affected contract was a third-party external adapter and had zero effect on Aave v3.","heading":"Incident Overview","severity":"high","sources":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"Aave Founder Clarifies That v3 Is Not Affected by Recent Attack on Third-Party Module — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"}]},{"content":"The vulnerability was an access control flaw in the FlashLoopAdapter contract's open() and close() functions. Rather than independently verifying the caller's identity, these functions checked only whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true. Because this check relied entirely on the calling contract's own response, an attacker could deploy a fake Safe contract programmed to always return true when queried, bypassing authentication.\n\nOnce the fake Safe passed authentication, the attacker abused the module's _swap() function. This function executed a raw call to a caller-supplied swap router using fully attacker-controlled calldata. The attacker set the router address to a victim Safe wallet and the calldata to execTransactionFromModule — a Safe function that permits an enabled module to execute transactions on the Safe's behalf. Because FlashLoopAdapter was already legitimately enabled as a module on the victim Safes, the adapter's existing permissions were effectively turned into a remote-control mechanism over the victims' assets.\n\nThe root cause is a classic reentrancy-adjacent pattern: caller-controlled input to a privileged function with insufficient identity validation. The vulnerable contract address is reported as 0x16bb8b912da187870c23ec6756bb3fad061283d8.","heading":"Technical Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"}]},{"content":"The attack was executed in a single Ethereum transaction on October 1, 2026. The attacker (wallet address 0x42c2633438609881c8fBAb82414eb9A0c45F9353) carried out the following steps:\n\n1. Obtained a WETH flash loan from Morpho protocol.\n2. Used the borrowed funds to repay approximately 1,335 WETH of outstanding Aave v3 debt held by the two victim Safe wallets. Repaying this debt freed the collateral backing it.\n3. Exploited the access control flaw to call execTransactionFromModule on the victim Safes, withdrawing approximately 1,306.48 weETH from the first Safe (0xcfedf95a3653a128dfc2e4288758a1a1850d169f) and 6.4 weETH from the second Safe (0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520).\n4. Repaid the Morpho flash loan from the withdrawn collateral.\n5. Retained approximately 114.09 ETH as net profit, worth approximately $305,000–$310,000 at the time.\n\nThe two on-chain transactions referenced in reporting include hash 0x75328f916b1a0878724d364da5eb12b255160b894cb36c63ed5d718efc616fc4 for the primary Safe withdrawal.","heading":"Attack Execution and Financial Impact","severity":"critical","sources":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"},{"credibility":2,"name":"Aave v3 Loop Safe Module Hacked, 114 ETH Stolen — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-v3-loop-safe-module-hacked-114-eth-stolen"},{"credibility":2,"name":"Aave Hack: FlashLoopAdapter Hits Two Safe Wallets — CryptoTimes (loop module article)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/aave-v3-loop-module-hacked-for-114-eth-aaves-pools-not-affected/"}]},{"content":"Multiple security analysts and the affected parties confirmed that neither Aave v3's core smart contracts nor Safe's core multisig infrastructure were exploited. The flaw existed exclusively within the FlashLoopAdapter third-party module. Aave founder Stani Kulechov stated publicly that the affected contract was 'a third party external adapter built on top of Aave' and had 'zero effect on Aave v3.' The Aave v3 lending pools continued to operate normally throughout the incident. Safe's core execution logic was not bypassed; the attacker abused the module permission system as designed, exploiting only the adapter's failure to validate caller identity prior to granting those permissions effect.\n\nThis distinction is significant for risk assessment: the vulnerability category is third-party integration risk, not a protocol-level flaw in Aave or Safe.","heading":"Scope: Aave v3 and Safe Infrastructure Not Compromised","severity":"medium","sources":[{"credibility":2,"name":"Aave Founder Clarifies That v3 Is Not Affected by Recent Attack on Third-Party Module — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"},{"credibility":2,"name":"Aave v3 Unaffected After Third Party Adapter Hack Hits Safe Wallets — Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-v3-unaffected-after-third-party-adapter-hack-hits-safe-wallets"},{"credibility":2,"name":"Aave founder: The Loop Safe Module is a third-party adapter — ChainCatcher","type":"news_article","url":"https://www.chaincatcher.com/en/article/2293674"}]},{"content":"Following the exploit, both victim Safe wallets disabled the vulnerable FlashLoopAdapter module to prevent further losses. The wallet owner, identified on-chain by the ENS name aavechan.eth, sent an on-chain message to the attacker's address offering a 10% whitehat bounty. Under the terms offered, the attacker could retain 11.41 ETH and was asked to return 102.69 ETH before October 3, 2026 at 18:00 UTC, with the offer stated to expire at that deadline.\n\nAs of the time of this investigation (October 2, 2026), no public reporting confirms whether the attacker accepted, declined, or ignored the bounty offer. The attacker's identity remains unknown. No law enforcement referral or on-chain tracing to a known entity has been publicly reported. No formal post-mortem from the module's developer has been published, and the module's creator has not been publicly identified in available sources.","heading":"Post-Incident Response and Recovery Efforts","severity":"high","sources":[{"credibility":2,"name":"FlashLoopAdapter Flaw Drains $305K From Aave-Linked Safe Wallets — Blockfence","type":"news_article","url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"Aave-Linked Module Bypassed Safe Wallet Security — DailyCoin","type":"news_article","url":"https://dailycoin.com/aave-safe-wallet-exploit"}]},{"content":"Available public sources do not identify the developer or development team responsible for the FlashLoopAdapter contract. No prior security audit of the FlashLoopAdapter contract has been referenced in any reporting. No GitHub repository, documentation site, or official project page for the module has been identified in public sources at the time of this investigation. The absence of disclosed authorship and audit history are themselves risk signals for third-party DeFi tooling. One report noted this incident resembles a pattern of third-party module vulnerabilities built on top of Aave v3, suggesting the exploit may not be isolated.","heading":"Audit and Development History","severity":"high","sources":[{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K from Aave-Linked Safe Wallets — Bitbase","type":"news_article","url":"https://www.bitbase.com/news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets"},{"credibility":2,"name":"FlashLoopAdapter Flaw Drains $305K From Aave-Linked Safe Wallets — Blockfence","type":"news_article","url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"}]},{"content":"Blockchain security firm SlowMist was the primary source of technical analysis for this incident, issuing an alert identifying the access control vulnerability in the FlashLoopAdapter's open() and close() functions. SlowMist confirmed the attacker address as 0x42c2633438609881c8fBAb82414eb9A0c45F9353 and the vulnerable contract address as 0x16bb8b912da187870c23ec6756bb3fad061283d8. Security monitoring platform Defimon Alerts and security firm ExVul are also cited by multiple outlets as having identified the vulnerability post-incident. No pre-incident disclosure or responsible disclosure process has been reported.","heading":"Security Firm Analysis","severity":"high","sources":[{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Attacked, 114 ETH Stolen — PANews","type":"news_article","url":"https://panews.io/articles/01a0faa1-55ab-77fc-b694-4000ec063ee6"},{"credibility":3,"name":"BSCN on X: Aave V3 Safe Module Hit By Access Control Exploit","type":"social_media","url":"https://x.com/BSCNews/status/2105892590315028553"}]}],"sources_used":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets — crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"},{"credibility":2,"name":"Aave v3 Loop Module Hacked for 114 ETH. Aave's Pools Were Used, Not Broken — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/aave-v3-loop-module-hacked-for-114-eth-aaves-pools-not-affected/"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen — mpost.io","type":"news_article","url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"credibility":2,"name":"Aave Founder Clarifies That v3 Is Not Affected by Recent Attack on Third-Party Module — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"},{"credibility":2,"name":"Aave v3 Loop Safe Module Hacked, 114 ETH Stolen — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-v3-loop-safe-module-hacked-114-eth-stolen"},{"credibility":2,"name":"Aave v3 Unaffected After Third Party Adapter Hack Hits Safe Wallets — Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-v3-unaffected-after-third-party-adapter-hack-hits-safe-wallets"},{"credibility":2,"name":"FlashLoopAdapter Exploit Results in $305K Loss from Ethereum Safe Wallets — Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-linked-safe-wallet-module-exploited-over-300000-drained-from-two-wallets-pnr-da8312b502859cda1512ea4e"},{"credibility":2,"name":"FlashLoopAdapter Flaw Drains $305K From Aave-Linked Safe Wallets — Blockfence","type":"news_article","url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave-Linked Module Bypassed Safe Wallet Security — DailyCoin","type":"news_article","url":"https://dailycoin.com/aave-safe-wallet-exploit"},{"credibility":2,"name":"Aave V3 Exploit Targets FlashLoopAdapter Draining $300K — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/10/02/aave-v3-exploit-flashloopadapter/"},{"credibility":2,"name":"Aave-Linked Safe Wallets Drained of Up to $310K in FlashLoopAdapter Exploit — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/aave-linked-safe-wallets-drained-of-up-to-310k-in-flashloopadapter-exploit"},{"credibility":2,"name":"Aave founder: The Loop Safe Module is a third-party adapter — ChainCatcher","type":"news_article","url":"https://www.chaincatcher.com/en/article/2293674"},{"credibility":2,"name":"SlowMist: Aave v3 Loop Safe Module Attacked, 114 ETH Stolen — PANews","type":"news_article","url":"https://panews.io/articles/01a0faa1-55ab-77fc-b694-4000ec063ee6"},{"credibility":3,"name":"BSCN on X: Aave V3 Safe Module Hit By Access Control Exploit","type":"social_media","url":"https://x.com/BSCNews/status/2105892590315028553"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K from Aave-Linked Safe Wallets — Bitbase","type":"news_article","url":"https://www.bitbase.com/news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets"},{"credibility":2,"name":"Aave V3 Loop Module Exploit Drains About 114 ETH — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/technology/26274"}],"summary":"FlashLoopAdapter is a third-party Safe module designed to automate the opening and closing of leveraged positions on Aave v3. On October 1, 2026, an attacker exploited a critical access control vulnerability in the module's open() and close() functions, draining approximately 114.09 ETH (estimated at $305,000–$310,000) from two Safe multisig wallets on Ethereum. Neither Aave v3 nor Safe's core infrastructure was compromised; the flaw resided entirely within the third-party adapter.","timeline":[{"date":"2026-10-01","event":"Attack executed at approximately 15:08:57 UTC. Attacker (0x42c2633438609881c8fBAb82414eb9A0c45F9353) deployed a fake Safe contract, obtained a Morpho WETH flash loan, repaid approximately 1,335 WETH of Aave v3 debt across two victim Safes, and withdrew approximately 1,306.48 weETH and 6.4 weETH, retaining ~114.09 ETH as net profit. Both victim Safes disabled the FlashLoopAdapter module after the attack.","source":"crypto.news / SlowMist","source_url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"date":"2026-10-01","event":"SlowMist issues public alert identifying the access control vulnerability and publishing attacker and contract addresses.","source":"mpost.io","source_url":"https://mpost.io/slowmist-aave-v3-loop-safe-module-exploited-via-access-control-flaw-114-09-eth-stolen/"},{"date":"2026-10-02","event":"Aave founder Stani Kulechov publicly clarifies that Aave v3 core contracts were unaffected and describes the FlashLoopAdapter as a third-party external adapter.","source":"KuCoin News","source_url":"https://www.kucoin.com/news/flash/aave-founder-clarifies-v3-not-affected-by-recent-attack-on-third-party-module"},{"date":"2026-10-02","event":"Wallet owner aavechan.eth sends on-chain message to attacker offering a 10% whitehat bounty: attacker may retain 11.41 ETH and must return 102.69 ETH before October 3 at 18:00 UTC.","source":"Blockfence / Crypto Briefing","source_url":"https://blockfence.io/flashloopadapter-flaw-drains-305k-from-aave-linked-safe-wallets/"},{"date":"2026-10-02","event":"Multiple crypto news outlets publish full coverage. Incident is categorized as a third-party module exploit, not an Aave v3 or Safe infrastructure breach.","source":"CryptoTimes / Blockonomi / crypto.news / Crypto Briefing","source_url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"}]},"v":1}