Particle.news

FlashLoopAdapter Access Flaw Drains $305K From Two Safe Wallets

A flash loan with forged module authentication allowed an attacker to free collateral then extract funds, highlighting the danger of poorly validated third‑party Safe modules.

Overview

  • Security monitors traced the single‑transaction attack to Oct. 1 when an exploiter used a Morpho WETH flash loan to repay about 1,335 WETH of on‑chain Aave debt and free collateral from two Safe multisigs.
  • The attacker deployed a fake Safe contract that spoofed Safe authentication and tricked the FlashLoopAdapter into calling execTransactionFromModule to withdraw roughly 1,306 weETH from one Safe and about 6.4 weETH from the second.
  • Post‑incident analysis found the root cause in the adapter’s open() and close() access checks, which relied on ISafe(msg.sender).isModuleEnabled(...) and accepted caller‑controlled responses without verifying the caller was a real Safe.
  • The attacker’s net take was about 114.1 ETH, roughly $305,000, and the affected Safes disabled the FlashLoopAdapter module while investigators and security firms continue to analyze the breach.
  • Aave’s core v3 contracts were not compromised according to the protocol’s founder, but the incident underscores that modules granted broad execution rights can bypass multisig protections and that strict caller validation and audits are essential.