Overview
- The exploit, which occurred Thursday, Oct. 1, used a fake Safe contract to bypass FlashLoopAdapter’s open()/close() checks and let the module execute transactions from two enabled Safes.
- The attacker took a Morpho WETH flash loan to repay roughly 1,335 WETH of Aave debt, freed collateral and withdrew about 1,306 weETH from one Safe and 6.4 weETH from a second Safe.
- After repaying the flash loan and converting assets, the attacker retained roughly 114.1 ETH, with combined victim losses estimated at about $305,000–$310,000.
- Security firms SlowMist and Defimon Alerts identified the attacker address (0x42c2633438609881c8fBAb82414eb9A0c45F9353) and the vulnerable module contract (FlashLoopAdapter: 0x16bb8b912da187870c23ec6756bb3fad061283d8), and the two affected Safes disabled the module.
- Aave’s core v3 contracts were not compromised and the incident underscores a recurring risk where third‑party Safe modules with broad execution rights, not the base protocol, become the primary attack surface for multisig wallets.