FlashLoopAdapter (Aave v3 loop Safe module) hack — October 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 1, 2026 |
| Target type | Individual holder |
| Loss | $306,700Price at time of incident |
| Method | Access control flawFlashLoopAdapter's open() and close() accepted any calling contract that claimed to have the adapter enabled as a Safe module, and its swap step called a router address with calldata both chosen by the caller; pointing the router at a victim Safe let the attacker run transactions through the adapter's module rights |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
Two Safe multisig wallets that used FlashLoopAdapter, a third-party Safe module for opening and closing leveraged loop positions on Aave v3, lost about 114.1 ETH, roughly $306,700, on 1 October 2026. The attack was a single Ethereum transaction at 15:08:47 UTC in block 26,098,264, and Defimon Alerts flagged it ten seconds later. Aave itself was not exploited: its founder Stani Kulechov said the contract was a third-party adapter built on top of Aave with no effect on Aave v3. Who built the adapter and who controls the two wallets has not been disclosed.
According to SlowMist, the adapter's open() and close() functions checked only that the calling contract reported the adapter as one of its enabled Safe modules, a question a fake Safe can simply answer yes to. The adapter's internal swap step then called a router address with calldata, both supplied by the caller. The attacker deployed a fake Safe, set the router to a victim's Safe and the calldata to execTransactionFromModule, and because the adapter was an enabled module on the victims' wallets, the Safes carried out whatever it passed them. To free the collateral, the attacker flash-borrowed WETH from Morpho, repaid about 1,335 WETH of the victims' Aave debt, withdrew their weETH collateral and repaid the flash loan in the same transaction.
The gross flows were far larger than the loss. What the attacker kept was the difference between the 1,449.35 WETH its contract received from the swaps and the 1,335.26 WETH it paid into Aave: 114.10 WETH, which this registry read from the transaction's logs and which matches SlowMist's figure of 114.09 ETH. The amount recorded here values it at the ether price of that hour. No recovery, bounty offer or statement from the adapter's developers has been reported.
Sources
- SlowMistSecondary · retrieved 2026-10-02
- crypto.newsSecondary · retrieved 2026-10-02
- CryptoSlateSecondary · retrieved 2026-10-02
- CryptonewsSecondary · retrieved 2026-10-02
- Ethereum transaction logs, read by this registryOn-chain · retrieved 2026-10-02
Changes to this entry
- Recorded the day after the exploit. The amount is the 114.10 WETH the attack contract kept, read by this registry from the transaction's logs and valued at the ether price of that hour; the 1,335 WETH of debt repaid and the weETH withdrawn are gross flows and are not counted.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "FlashLoopAdapter (Aave v3 loop Safe module) hack — October 2026", iTokenly, accessed 2026-10-02, https://itokenly.com/hacks/flashloopadapter-aave-safe-modulehttps://itokenly.com/hacks/flashloopadapter-aave-safe-modulePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.