A third-party Safe module used to automate leveraged positions on Aave v3 was exploited for approximately 114.09 ETH, around $305,000, blockchain security firm SlowMist said on October 2 — the latest in a string of incidents targeting the module layer of Safe multisig wallets rather than the protocols beneath them.

The targeted contract, FlashLoopAdapter, is an external Safe module that automates opening and closing leveraged staking cycles around Aave v3. The attack was first detected by Defimon Alerts on October 1. Aave founder Stani Kulechov confirmed that the exploited code is not part of Aave v3 itself but a third-party adapter built on top, "zero effect on Aave v3."

A spoofable check and a raw call

According to SlowMist's analysis, the root cause sits in the access controls of the adapter's open() and close() functions. Rather than independently verifying the caller, the functions only check that ISafe(msg.sender).isModuleEnabled(address(this)) returns true — a check an attacker can satisfy by deploying a fake Safe contract programmed to always return true.

The module's _swap() function then executes a raw call to a caller-supplied router with fully attacker-controlled calldata. By pointing that call at a victim Safe with the calldata execTransactionFromModule — a function that lets an enabled module execute transactions — the attacker effectively converted the adapter's own permissions into remote control over the wallets. Because FlashLoopAdapter was already enabled as a module on both targeted Safes, the calls were accepted.

The attack chain

The attacker took a Morpho WETH flash loan and repaid roughly 1,335 WETH of Aave debt belonging to the larger of the two Safes, unlocking the leveraged position's collateral. The Safe was then directed to withdraw about 1,306 weETH to an attacker-controlled address. A second Safe lost an additional 6.4 weETH through the same mechanism; Defimon Alerts noted both wallets shared a single owner. After settling the flash loan, the attacker retained around 114.1 ETH. On-chain identifiers: attacker address 0x42c2...9353, vulnerable contract 0x16bb...83d8.

The structure mirrors a familiar 2026 pattern: audited core protocols left intact while the bolt-on layer — modules, adapters, oracle integrations — fails. A similar weakness surfaced in September, when a Safe exploit involving roughly 2,900 rsETH was traced to inadequate authorization checks in an executor contract tied to an enabled module. In May, attackers drained about $3 million from 86 wallets by abusing SquidRouterModule, and Gnosis Pay users were urged to withdraw funds after a flaw was found in its Zodiac delay module.

Safe modules can execute transactions from a wallet without the standard owner-approval flow, which is precisely what makes them powerful and dangerous: a single flaw in a module's authentication logic can expose every asset under its control.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.