Skip to content
Markets 24H · USDT TR EN Updated 09:54
3 min read

DeFi News

Two Safe wallets lose 114 ETH as Aave clarifies exposure

A broken purple connection between an intact Aave-marked structure and two glass wallets
Save article

Key takeaways

  • SlowMist put losses across two Safe wallets at about 114.09 ETH.
  • The October 1 attack targeted FlashLoopAdapter, a third-party contract.
  • Stani Kulechov and SlowMist said Aave V3 contracts were unaffected.

The attacker repaid debt to release collateral before taking the remaining funds. Researchers traced the flaw to authorization checks in an external module built on top of Aave.

An external module used to manage Aave V3 positions on Ethereum was exploited, leaving two Safe wallets with losses of about 114.09 ETH. In its October 2 analysis, SlowMist traced the flaw to access controls in FlashLoopAdapter. Aave founder Stani Kulechov said the same day that the core protocol contracts were unaffected.

The attack took place on October 1. Defimon Alerts’ initial report valued the loss at roughly $305,000 at the time of the incident and said both wallets had the same single owner. SlowMist’s analysis the following day corroborated the ETH-denominated loss and the nature of the vulnerability.

Aave points to an external adapter

FlashLoopAdapter is a separate contract that automates leveraged positions involving borrowing and redepositing collateral through Aave. Its association with the protocol does not place the vulnerability inside Aave V3’s own code.

“it’s third party external adapter built on top of Aave, zero effect on Aave v3.”

Stani Kulechov, in an October 2 post on X

SlowMist made the same distinction in a follow-up to its initial alert. The researchers identified a way to bypass the adapter’s checks on whether a caller was authorized to act. The statements reviewed do not report a general loss of funds from Aave’s lending pools.

Debt was repaid before collateral was withdrawn

According to Defimon, the attacker used a Morpho flash loan to repay about 1,335 WETH of debt held by one of the wallets. Repayment released collateral in its Aave position. The attacker then withdrew approximately 1,306 weETH from that wallet and a further 6.4 weETH from the second.

WETH and weETH are different tokens, so their quantities cannot simply be added as though they were the same unit. Part of the withdrawn assets went toward settling the debts and the flash loan. SlowMist put the amount ultimately retained by the attacker at around 114.09 ETH.

The 1,335 WETH figure is not the net loss. The larger debt and collateral movements describe amounts passing through the unwinding of a leveraged position. The roughly $305,000 loss estimate reflects the value at the time of the incident, rather than a fresh calculation using the current ETH price.

The risk lay in an enabled wallet module

Safe wallets can authorize enabled modules to execute transactions. FlashLoopAdapter held that permission in both affected wallets. SlowMist’s findings describe an attacker abusing the adapter’s authorization checks to make the wallets act, rather than stealing their private keys.

For readers following DeFi news, the incident illustrates the different risks of a lending protocol and the automation connected to it. Aave V3 remaining unaffected does not undo the losses suffered by wallets using the external module. The statements we reviewed contain no announcement of reimbursement or a completed recovery of the funds.

SlowMist’s technical alert identifies the affected contract and each of the two wallets:

From X

SlowMist’s technical alert on the FlashLoopAdapter incident

View on X

The post loads from X when you open it.

PRIVACY PREFERENCES