Attacker Drained $305,000 From Safe Wallets

An exploit targeting a FlashLoopAdapter contract led to the theft of assets on the Ethereum blockchain.

Updated on Oct. 2, 2026 in Cybersecurity

Isometric editorial illustration of interlocking iron chains and hexagonal braces, representing secure blockchain smart contract verification infrastructure.
A vulnerability in the FlashLoopAdapter contract allowed an attacker to drain $305,000 from Safe wallets on the Ethereum blockchain. AI Illustration. Upload story photo >

Live Poll

Do you trust third-party apps connected to your digital wallet to keep your assets secure?

An attacker compromised two Safe wallets by exploiting a vulnerability in the FlashLoopAdapter contract. The security breach resulted in the loss of approximately $305,000 in digital assets.

Why it matters

The incident occurred because the adapter contract failed to verify that callers were legitimate Safe wallets, allowing the attacker to bypass authentication. This highlights the critical importance of rigorous validation in smart contract integrations.

The attacker utilized a fake Safe contract to return a successful status during authentication checks, enabling the withdrawal of 1,306 weETH from the first wallet and 6.4 weETH from the second. The exploiter retained 114.09 ETH after the transaction.

The players

Safe

Safe is a prominent platform providing smart contract-based account abstraction wallets on the Ethereum blockchain.

Aave

Aave is a decentralized finance protocol that allows users to lend and borrow a variety of cryptocurrencies.

Defimon Alerts

Defimon Alerts is a security monitoring service that tracks and reports on exploits and suspicious activities across blockchain networks.

The details

By deploying a fake contract to bypass authentication checks within the FlashLoopAdapter, the attacker successfully called the execTransactionFromModule function. The perpetrator also used a Morpho WETH flash loan to repay 1,335 WETH in Aave debt to unlock collateral.

Timeline

  1. The attack was detected by Defimon Alerts at 15:08:57 UTC on October 1, 2026.

The Tech Race

This exploit highlights the ongoing vulnerability of custom adapter contracts that sit between decentralized applications and established security standards like the Aave v3 protocol. As DeFi becomes more interconnected, these integration points continue to represent the most frequent attack vectors in the ecosystem.

Users of smart contract wallets should remain cautious when granting permissions to third-party adapter contracts that claim to interact with their accounts. Always verify that the smart contracts being used for transactions have undergone independent, third-party security audits.

The takeaway

Smart contract security often depends on the weakest integration point, making robust verification essential for all wallet modules. Users should practice wallet hygiene by regularly auditing the permissions and modules authorized on their accounts.

Further reading

For more information on current threats and digital asset protection, visit our Cybersecurity section.

Live Poll

Do you trust third-party apps connected to your digital wallet to keep your assets secure?