Two Secure Wallets Lose $305,000 in FlashLoopAdapter Assault

A customized FlashLoopAdapter used to handle leveraged Aave V3 positions was exploited in a hack on Ethereum, leaving two Secure wallets with an estimated internet lack of 114.09 ETH, or about $305,000.

The attacker spoofed a Secure authentication test, then used a Morpho WETH flash mortgage to repay debt and unlock collateral. The roughly 1,306 weETH withdrawn from one pockets was a gross transaction move, not the attacker’s internet proceeds.

SlowMist: Aave v3 Loop Secure Module Exploited, Roughly 114.09 ETH Stolen
SlowMist issued a safety alert stating that Aave v3 Loop Secure Module was exploited by means of an access-control vulnerability in FlashLoopAdapter’s open() and shut() features. The attacker allegedly… pic.twitter.com/a97iMcGWnI

— Wu Blockchain (@WuBlockchain) October 2, 2026

Defimon Alerts mentioned it detected the Ethereum assault at 15:08:57 UTC on Thursday, October 1. SlowMist revealed its evaluation on Friday, October 2, figuring out a weak point within the adapter’s open and shut features. A malicious contract might pose as a Secure and return that worth, passing a test meant to substantiate {that a} reliable pockets had enabled FlashLoopAdapter.

The AAVE hack attacker-controlled contract additionally provided the adapter’s swap router and calldata. It pointed the router at a sufferer Secure and set the calldata to invoke execTransactionFromModule. As a result of FlashLoopAdapter was already enabled on that Secure, the pockets accepted the decision as a licensed module transaction.

The sequence turned a slim authentication flaw into entry to wallet-controlled collateral. The episode underscores how pockets permissions and execution paths matter alongside the safety of the lending protocol itself, a priority additionally central to custody infrastructure and authentication controls.

Earn $50 and Enter $300K Prize Draw on EdgeX

Flash Mortgage Hack Repaid Aave Debt Earlier than Collateral Was Withdrawn

aave logoAave (AAVE)24h7d30d1yAll time

The attacker used a Morpho flash mortgage denominated in WETH to repay roughly 1,335 WETH of Aave debt related to the bigger Secure. Reimbursement freed collateral tied to its leveraged place, permitting roughly 1,306 weETH to be withdrawn. A second Secure misplaced about 6.4 weETH by means of the identical weak module.

Each affected Safes had the identical single proprietor. After the borrowed funds have been settled and a few property transformed, the attacker retained roughly 114.09 ETH, which safety stories valued at about $305,000.

A FlashLoopAdapter hack on Ethereum caused an estimated $305,000 net loss for two Safe wallets, while Aave says its core contracts unaffected.

The excellence between gross motion and realized loss is materials. The big collateral withdrawal enabled the debt reimbursement and place unwind; it shouldn’t be learn as the quantity stolen. The reported internet proceeds have been the ETH remaining after these transaction steps.

Commerce AAVE on Bybit and Get a Likelihood to Win Our $1,000 USDT Airdrop

Aave Says Core Contracts Not Affected

Aave founder and CEO Stani Kulechov mentioned the weak part was an exterior integration moderately than an Aave V3 contract and had “zero impact on Aave v3.”

This isn’t Aave v3 contract, it’s third social gathering exterior adapter constructed on high of Aave, zero impact on Aave v3.

— Stani (@StaniKulechov) October 2, 2026

SlowMist labeled the incident as a smart-contract vulnerability and attributed the bypass to the spoofable Secure test. Defimon described FlashLoopAdapter as a Secure module for opening and shutting leveraged Aave V3 loops and estimated the loss at roughly $305,000.

FlashLoopAdapter is a customized contract constructed on Aave V3 for managing leveraged positions in Safes that enabled it. Secure modules can execute pockets transactions with out requiring the usual proprietor transaction move every time, which helps automation but in addition provides a licensed module a path to pockets property.

Right here, the module’s permission was not itself the reported bug; the adapter’s caller-authentication and execution logic have been. The case is due to this fact a DeFi safety failure on the integration layer, not proof that Aave V3’s lending swimming pools have been compromised.

The first supply additionally notes a separate September Secure-wallet incident involving roughly 2,900 rsETH and weak authorization in an executor linked to an enabled module, however the two incidents concerned distinct contracts and assault paths.

Uncover: The Greatest Token Presales

The publish Two Secure Wallets Lose $305,000 in FlashLoopAdapter Assault appeared first on Cryptonews.

HOT news

Related posts

Latest posts

Large Ethereum Awakening: Why 580M in Dormant ETH Simply Moved With out Crashing Worth

OG Ethereum buyers awakened a number of days in the past by finishing the largest transfer of long-dormant cash since early June. Nevertheless, the...

Lyft agrees to pay $272.5 million to settle employee classification lawsuit

Uber and Lyft had been sued by the state of California in 2020 for misclassifying workers as contractors.

Bitcoin Rejected at $87K Regardless of Comfortable PCE and Jobs Knowledge as QNT, NIGHT Explode: Weekly Crypto Recap

It was one other main week for the crypto market, which ended with what was presupposed to be excellent news for risk-on belongings, nevertheless...

SEC Proposes Guidelines That Might Change How Funds Custody Crypto

Regulatory efforts proceed following the CLARITY Act’s failure to advance. The US Securities and Change Fee has now proposed new guidelines to create a...

Apple acknowledges AT&T community bug on iPhone 18 Professional Max

Experiencing SOS mode in your iPhone 18 Professional Max with AT&T? Apple confirms a {hardware} problem and particulars who wants a substitute.

Want to stay up to date with the latest news?

We would love to hear from you! Please fill in your details and we will stay in touch. It's that simple!