Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
453252984
Off-chain at
2026-10-04T12:12:11.157Z
Anchored at
2026-10-04T12:12:30.588Z
Block time
—

Independent verification

1. Database (off-chain)
HGBvCiu74GLm2c4H1t2QjQB1psiF2XTnbmqisXquLN7e
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (12135 chars)
{"actor":"system:backfill","investigation_id":"5550dd6b-169c-466a-af69-024c251761d4","kind":"publish","page_slug":"flashloopadapter","published_at":"2026-10-04T12:12:11.058Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"FlashLoopAdapter","sections":[{"content":"FlashLoopAdapter is a smart-contract module built to be enabled on Safe (formerly Gnosis Safe) multisignature wallets, allowing those wallets to open and close leveraged borrowing/lending positions on Aave V3 using flash loans. It is a third-party integration built on top of Aave's infrastructure rather than a component of Aave's own audited core contracts. Multiple outlets reporting on the October 2026 exploit, including Cryptonomist and CryptoTimes, describe it this way, and Aave founder Stani Kulechov publicly distinguished it from Aave's core protocol, stating it was a 'third party external adapter built on top of Aave, zero effect on Aave v3.' No public information was found identifying the individual or team that developed and deployed FlashLoopAdapter, and no search turned up evidence that the contract had undergone a third-party security audit prior to the exploit.","heading":"What FlashLoopAdapter Is","severity":"medium","sources":[{"credibility":2,"name":"Aave V3 Exploit Targets FlashLoopAdapter Draining $300K - Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/10/02/aave-v3-exploit-flashloopadapter/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"}]},{"content":"On October 1, 2026, an attacker exploited FlashLoopAdapter to drain funds from two Safe wallets that had the module enabled, for a combined loss reported at roughly $305,000 to $310,000 (approximately 114 ETH retained by the attacker after repaying a flash loan). Cryptonomist reported that 'the incident unfolded on October 1 when an attacker-controlled contract managed to slip past the access checks built into FlashLoopAdapter.' The attacker used a WETH flash loan sourced from Morpho, repaid approximately 1,335 WETH of Aave debt owed by the victim wallets, and in doing so freed roughly 1,306.48 weETH of collateral from one Safe and about 6.4 weETH from a second, which were then diverted to the attacker. Security monitoring service Defimon Alerts and security firm SlowMist both flagged the incident. A detailed account of this specific incident, including its own assessment and trust implications, is published separately at /flashloopadapter-aave-v3-safe-module-exploit; this section summarizes the event only to establish why FlashLoopAdapter is notable as an entity.","heading":"October 2026 Exploit","severity":"critical","sources":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets - crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"Aave V3 Exploit Targets FlashLoopAdapter Draining $300K - Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/10/02/aave-v3-exploit-flashloopadapter/"}]},{"content":"According to a proof-of-concept writeup submitted to the DeFiHackLabs repository and corroborated by SlowMist's analysis, FlashLoopAdapter's open() and close() functions authenticated callers by asking the calling contract whether it considered the adapter an enabled module (via a call equivalent to ISafe(msg.sender).isModuleEnabled(address(this))), rather than independently verifying that the caller was a genuine, previously-deployed Safe. This allowed an attacker to deploy a single malicious contract that simultaneously impersonated a Safe, a flash-loan provider, and a liquidity pool, and that simply returned 'true' to the enablement check. A second flaw compounded this: the adapter's internal swap-routing function executed raw, low-level calls to a caller-supplied address with caller-supplied calldata and no allowlist, which let the attacker point the 'router' parameter at a real victim Safe and supply calldata invoking execTransactionFromModule — a legitimate Safe function that allows an enabled module to execute arbitrary transactions on the Safe's behalf. Because FlashLoopAdapter was genuinely enabled on the victim Safes, those wallets executed the attacker's instructions, repaying debt and releasing collateral to the attacker. No private keys or signer approvals were compromised; the exploit relied entirely on the adapter's flawed authentication and unconstrained external call logic.","heading":"Technical Root Cause","severity":"high","sources":[{"credibility":2,"name":"Add FlashLoopAdapter exploit PoC - broken self-attestation, ~114.1 ETH on Ethereum - DeFiHackLabs PR #1287","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1287"},{"credibility":2,"name":"SlowMist identifica una falla en FlashLoopAdapter detrás del robo de 114 ETH de dos monederos seguros","type":"news_article","url":"https://kucoin.com/es/news/flash/slowmist-identifies-flashloopadapter-flaw-behind-114-eth-theft-from-two-safe-wallets"}]},{"content":"Following the exploit, the two affected Safe wallets reportedly disabled the vulnerable FlashLoopAdapter module to prevent further losses, as reported by Crypto Briefing. Aave founder Stani Kulechov publicly stated that the contract involved was a third-party adapter built on top of Aave and had no effect on Aave V3's own lending pools, a position echoed by multiple outlets including Crypto Economy and Blockonomi, which both ran coverage emphasizing that Aave's core contracts were unaffected. As of the most recent reporting found, the identity of the attacker had not been publicly confirmed, the total number of Safe wallets that had enabled FlashLoopAdapter prior to detection was unclear, and no confirmation of fund recovery or compensation for victims had been reported.","heading":"Response and Scope of Impact","severity":"high","sources":[{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"Aave v3 Unaffected by $305K Safe Exploit - Crypto Economy","type":"news_article","url":"https://crypto-economy.com/aave-v3-unaffected-by-305k-safe-exploit/"},{"credibility":2,"name":"Aave v3 Unaffected After Third Party Adapter Hack Hits Safe Wallets - Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-v3-unaffected-after-third-party-adapter-hack-hits-safe-wallets"}]},{"content":"No publicly available source identifies who built, maintains, or governs FlashLoopAdapter, and no evidence of an independent security audit was found in available reporting. Commentary accompanying the exploit coverage, including from SlowMist's analysis as relayed by KuCoin's news desk, framed the incident as illustrative of a broader pattern: audited core DeFi protocols such as Aave can be secure while third-party automation modules built on top of them, which inherit significant execution privileges once enabled on a user's wallet, may not receive comparable scrutiny. This absence of identifiable ownership and audit history is itself a relevant trust signal for an entity that, once enabled, could execute arbitrary transactions on a user's Safe wallet.","heading":"Transparency and Governance Concerns","severity":"medium","sources":[{"credibility":2,"name":"SlowMist identifica una falla en FlashLoopAdapter detrás del robo de 114 ETH de dos monederos seguros","type":"news_article","url":"https://kucoin.com/es/news/flash/slowmist-identifies-flashloopadapter-flaw-behind-114-eth-theft-from-two-safe-wallets"}]}],"sources_used":[{"credibility":2,"name":"FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets - crypto.news","type":"news_article","url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"credibility":2,"name":"Aave v3 exploit drains up to $310K after Safe module attack - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/aave-v3-safe-module-exploit-310k/"},{"credibility":2,"name":"Aave V3 Exploit Targets FlashLoopAdapter Draining $300K - Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/10/02/aave-v3-exploit-flashloopadapter/"},{"credibility":2,"name":"FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/"},{"credibility":2,"name":"Aave v3 Loop Module Hacked for 114 ETH. Aave's Pools Were Used, Not Broken. - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/aave-v3-loop-module-hacked-for-114-eth-aaves-pools-not-affected/"},{"credibility":2,"name":"Aave v3 Unaffected by $305K Safe Exploit - Crypto Economy","type":"news_article","url":"https://crypto-economy.com/aave-v3-unaffected-by-305k-safe-exploit/"},{"credibility":2,"name":"Aave v3 Unaffected After Third Party Adapter Hack Hits Safe Wallets - Blockonomi","type":"news_article","url":"https://blockonomi.com/aave-v3-unaffected-after-third-party-adapter-hack-hits-safe-wallets"},{"credibility":2,"name":"SlowMist identifica una falla en FlashLoopAdapter detrás del robo de 114 ETH de dos monederos seguros","type":"news_article","url":"https://kucoin.com/es/news/flash/slowmist-identifies-flashloopadapter-flaw-behind-114-eth-theft-from-two-safe-wallets"},{"credibility":2,"name":"Add FlashLoopAdapter exploit PoC - broken self-attestation, ~114.1 ETH on Ethereum - DeFiHackLabs PR #1287","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1287"}],"summary":"FlashLoopAdapter is a third-party Safe (Gnosis Safe) module used to open and close leveraged positions on Aave V3. It is not an Aave or Safe product. On October 1, 2026, an access-control flaw in the module was exploited, draining roughly 114 ETH (about $305,000) from two Safe wallets that had enabled it. A detailed incident writeup exists at /flashloopadapter-aave-v3-safe-module-exploit; this page covers FlashLoopAdapter as an entity rather than restating that page's findings or score.","timeline":[{"date":"2026-10-01","date_evidence":"The incident unfolded on October 1 when an attacker-controlled contract managed to slip past the access checks built into FlashLoopAdapter.","event":"Attacker exploits an access-control flaw in FlashLoopAdapter, using a Morpho flash loan to repay Aave debt on two Safe wallets and withdraw their freed collateral, netting roughly 114 ETH (~$305K).","source":"Cryptonomist","source_url":"https://en.cryptonomist.ch/2026/10/02/aave-v3-exploit-flashloopadapter/"},{"date":"2026-10","event":"Security monitoring service Defimon Alerts and security firm SlowMist identify and publicize the exploit and its root cause in FlashLoopAdapter's authentication logic.","source":"crypto.news / KuCoin news (SlowMist analysis)","source_url":"https://crypto.news/flashloopadapter-exploit-drains-305k-from-aave-linked-safe-wallets/"},{"date":"2026-10","event":"Aave founder Stani Kulechov states publicly that FlashLoopAdapter is a third-party adapter built on top of Aave and that the exploit had no effect on Aave V3's core protocol.","source":"Crypto Economy","source_url":"https://crypto-economy.com/aave-v3-unaffected-by-305k-safe-exploit/"},{"date":"2026-10","event":"A proof-of-concept reproducing the exploit, attributing it to broken self-attestation and an unconstrained external call in FlashLoopAdapter, is submitted to the DeFiHackLabs public repository.","source":"GitHub - SunWeb3Sec/DeFiHackLabs PR #1287","source_url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1287"}]},"v":1}