Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Aave-Linked Exploit Drains $305K in ETH From Safe Wallet

Aave-Linked Exploit Drains $305K in ETH From Safe Wallet

CoinpediaCoinpedia2026/10/02 09:30
Story Highlights
  • FlashLoopAdapter exploit drains approximately 114.09 ETH worth nearly $305,000 from two Safe wallets.

  • Attackers spoofed a Safe authentication check before unlocking and withdrawing victim collateral.

  • Aave founder Stani Kulechov says core Aave V3 contracts remained completely unaffected.

A new Aave-related exploit has drained about 114 ETH worth $305,000 from two Safe wallets on Ethereum. The hacker exploited a third party adapter linked to Aave V3, bypassed a contract check, and unlocked the wallets’ collateral, leading to the loss.

Meanwhile, Aave founder Stani Kulechov said the attack did not affect Aave V3’s core contracts.

FlashLoopAdapter Exploit Drains 114 ETH

Blockchain security firm SlowMist reported that attackers exploited a weakness in FlashLoopAdapter, a third-party contract that manages leveraged positions on Aave V3.

The attacker first bypassed the Safe authentication check in a single transaction. They then used a Morpho WETH flash loan to repay debt and unlock collateral held by the affected wallets.

The attack ultimately drained around 114.09 ETH, worth roughly $305,000 to $310,000. The transaction withdrew around 1,306 weETH from one wallet, but that figure reflects gross movement, not the attacker’s final gain.

Fake Safe Check Opened the Door

The main weakness came from the adapter’s access-control system. It checked whether the module was enabled through a Safe contract. However, the attacker used a fake Safe that returned a positive response.

This allowed the attacker to bypass the check and control the router and transaction data used by the adapter. The attacker then set the router to the victim’s Safe and used the module’s execution function to move weETH and Aave collateral out of the wallets.

Both affected Safes belonged to the same owner. After the attack, the owner disabled the module to prevent further losses.

The stolen 114.09 ETH was then moved to a central address identified by security monitors as 0x7a83…42f1. 

The attacker later began sending the funds in batches toward Tornado Cash, a non-custodial privacy mixer, making the movement of the stolen funds harder to trace.

Aave V3 Contracts Remain Unaffected

“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said.

This means the exploit was linked to the custom automation layer rather than Aave V3’s main protocol contracts or liquidity pools.

News Image 0
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

ONDO falls below $0.5

金色财经•2026/10/02 18:25
ONDO falls below $0.5

Report: US-Iran conflict disrupts OPEC+ production increase schedule, capacity review postponed to mid-November

According to media reports, the capacity review work by OPEC+ has been delayed. Originally scheduled to be completed by the end of September 2026, it has now been postponed to mid-November. This theoretically still allows OPEC+ to discuss the related results at the plenary meeting in late November. The independent capacity assessment results will directly affect the production caps approved for each member country, and some member countries have already shown significant disagreements regarding quotas, putting pressure on the alliance’s stability.

华尔街见闻•2026/10/02 16:36