Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Aave-Linked Exploit Drains $305K in ETH From Safe Wallet

Aave-Linked Exploit Drains $305K in ETH From Safe Wallet

CoinpediaCoinpedia2026/10/02 09:30
Story Highlights
  • FlashLoopAdapter exploit drains approximately 114.09 ETH worth nearly $305,000 from two Safe wallets.

  • Attackers spoofed a Safe authentication check before unlocking and withdrawing victim collateral.

  • Aave founder Stani Kulechov says core Aave V3 contracts remained completely unaffected.

A new Aave-related exploit has drained about 114 ETH worth $305,000 from two Safe wallets on Ethereum. The hacker exploited a third party adapter linked to Aave V3, bypassed a contract check, and unlocked the wallets’ collateral, leading to the loss.

Meanwhile, Aave founder Stani Kulechov said the attack did not affect Aave V3’s core contracts.

FlashLoopAdapter Exploit Drains 114 ETH

Blockchain security firm SlowMist reported that attackers exploited a weakness in FlashLoopAdapter, a third-party contract that manages leveraged positions on Aave V3.

The attacker first bypassed the Safe authentication check in a single transaction. They then used a Morpho WETH flash loan to repay debt and unlock collateral held by the affected wallets.

The attack ultimately drained around 114.09 ETH, worth roughly $305,000 to $310,000. The transaction withdrew around 1,306 weETH from one wallet, but that figure reflects gross movement, not the attacker’s final gain.

Fake Safe Check Opened the Door

The main weakness came from the adapter’s access-control system. It checked whether the module was enabled through a Safe contract. However, the attacker used a fake Safe that returned a positive response.

This allowed the attacker to bypass the check and control the router and transaction data used by the adapter. The attacker then set the router to the victim’s Safe and used the module’s execution function to move weETH and Aave collateral out of the wallets.

Both affected Safes belonged to the same owner. After the attack, the owner disabled the module to prevent further losses.

The stolen 114.09 ETH was then moved to a central address identified by security monitors as 0x7a83…42f1. 

The attacker later began sending the funds in batches toward Tornado Cash, a non-custodial privacy mixer, making the movement of the stolen funds harder to trace.

Aave V3 Contracts Remain Unaffected

“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said.

This means the exploit was linked to the custom automation layer rather than Aave V3’s main protocol contracts or liquidity pools.

News Image 0
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

US Stock Market Movement | SpaceX (SPCX.US) rises over 5%, market value returns to 2 trillions dollars

On Friday, SpaceX (SPCX.US) opened higher and continued to rise, gaining over 5% at the time of reporting, with its market value exceeding 2 trillions USD.

智通财经•2026/10/02 14:26