Attacker Drained $305,000 From Safe Wallets
An exploit targeting a FlashLoopAdapter contract led to the theft of assets on the Ethereum blockchain.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Do you trust third-party apps connected to your digital wallet to keep your assets secure?
An attacker compromised two Safe wallets by exploiting a vulnerability in the FlashLoopAdapter contract. The security breach resulted in the loss of approximately $305,000 in digital assets.
Why it matters
The incident occurred because the adapter contract failed to verify that callers were legitimate Safe wallets, allowing the attacker to bypass authentication. This highlights the critical importance of rigorous validation in smart contract integrations.
The attacker utilized a fake Safe contract to return a successful status during authentication checks, enabling the withdrawal of 1,306 weETH from the first wallet and 6.4 weETH from the second. The exploiter retained 114.09 ETH after the transaction.
The players
Safe
Safe is a prominent platform providing smart contract-based account abstraction wallets on the Ethereum blockchain.
Aave
Aave is a decentralized finance protocol that allows users to lend and borrow a variety of cryptocurrencies.
Defimon Alerts
Defimon Alerts is a security monitoring service that tracks and reports on exploits and suspicious activities across blockchain networks.
The details
By deploying a fake contract to bypass authentication checks within the FlashLoopAdapter, the attacker successfully called the execTransactionFromModule function. The perpetrator also used a Morpho WETH flash loan to repay 1,335 WETH in Aave debt to unlock collateral.
Timeline
The attack was detected by Defimon Alerts at 15:08:57 UTC on October 1, 2026.
The Tech Race
This exploit highlights the ongoing vulnerability of custom adapter contracts that sit between decentralized applications and established security standards like the Aave v3 protocol. As DeFi becomes more interconnected, these integration points continue to represent the most frequent attack vectors in the ecosystem.
Users of smart contract wallets should remain cautious when granting permissions to third-party adapter contracts that claim to interact with their accounts. Always verify that the smart contracts being used for transactions have undergone independent, third-party security audits.
The takeaway
Smart contract security often depends on the weakest integration point, making robust verification essential for all wallet modules. Users should practice wallet hygiene by regularly auditing the permissions and modules authorized on their accounts.
Further reading
For more information on current threats and digital asset protection, visit our Cybersecurity section.
Live Poll
Do you trust third-party apps connected to your digital wallet to keep your assets secure?







