
The exploitation of a vulnerability in FlashLoopAdapter resulted in the loss of approximately $305,000 from two Safe wallets on Ethereum. The attacker used a flash loan to repay a debt in Aave, which amounted to about 1,335 WETH, before withdrawing around 1,306 weETH as collateral. The attacker also forced a second wallet, which suffered a loss of 6.4 weETH, to exploit the same vulnerability. The attack occurred on October 1, 2023, at 15:08:57 UTC. Aave founder Stani Kulechov noted that the affected contract was a third-party adapter built on Aave and had no impact on Aave v3. According to information from blockchain security firm SlowMist, the vulnerability stemmed from authentication flaws in the FlashLoopAdapter contract, allowing a fake wallet (Safe) to bypass access checks to the funds.
FlashLoopAdapter is designed to open and close borrowing positions through Aave v3, allowing for the management of borrowing and collateral strategies. The issue arose because the open() and close() functions did not verify whether the calling contract was indeed a legitimate Safe wallet, enabling the attacker to use a fake contract to gain access to functionality intended only for authorized wallets.
In addition to the aforementioned amount of 1,335 WETH used to repay the debt, the attacker subsequently received approximately 114.1 ETH, totaling about $305,000 at the time of the incident report. SlowMist estimates the total losses at $305,000. This case echoes previously recorded vulnerabilities related to permissions in Safe wallets. In September, another incident occurred involving improper authorization in a similar module, highlighting the need for enhanced security measures for adapters interacting with Safe wallets.



