UK Edition

Friday, 2 October 2026

Time Trade

Markets, trading & finance — British perspective

Crypto

Aave-Linked Exploit Drains $305K in ETH From Safe Wallet

Time Trade session note (2026-10-02): Aave-Linked Exploit Drains $305K in ETH From Safe Wallet FlashLoopAdapter exploit drains approximately 114.09 ETH worth nearly $305,000 from two Safe wallets.… Primary source: original at Coinpedia (coinpedia.org).

· Coinpedia

Aave-Linked Exploit Drains $305K in ETH From Safe Wallet
  • FlashLoopAdapter exploit drains approximately 114.09 ETH worth nearly $305,000 from two Safe wallets.

  • Attackers spoofed a Safe authentication check before unlocking and withdrawing victim collateral.

  • Aave founder Stani Kulechov says core Aave V3 contracts remained completely unaffected.

A new Aave-related exploit has drained about 114 ETH worth $305,000 from two Safe wallets on Ethereum. The hacker exploited a third party adapter linked to Aave V3, bypassed a contract check, and unlocked the wallets’ collateral, leading to the loss.

Meanwhile, Aave founder Stani Kulechov said the attack did not affect Aave V3’s core contracts.

FlashLoopAdapter Exploit Drains 114 ETH

Blockchain security firm SlowMist reported that attackers exploited a weakness in FlashLoopAdapter, a third-party contract that manages leveraged positions on Aave V3.

The attacker first bypassed the Safe authentication check in a single transaction. They then used a Morpho WETH flash loan to repay debt and unlock collateral held by the affected wallets.

The attack ultimately drained around 114.09 ETH, worth roughly $305,000 to $310,000. The transaction withdrew around 1,306 weETH from one wallet, but that figure reflects gross movement, not the attacker’s final gain.

Fake Safe Check Opened the Door

The main weakness came from the adapter’s access-control system. It checked whether the module was enabled through a Safe contract. However, the attacker used a fake Safe that returned a positive response.

This allowed the attacker to bypass the check and control the router and transaction data used by the adapter. The attacker then set the router to the victim’s Safe and used the module’s execution function to move weETH and Aave collateral out of the wallets.

Both affected Safes belonged to the same owner. After the attack, the owner disabled the module to prevent further losses.

The stolen 114.09 ETH was then moved to a central address identified by security monitors as 0x7a83…42f1.

The attacker later began sending the funds in batches toward Tornado Cash, a non-custodial privacy mixer, making the movement of the stolen funds harder to trace.

Aave V3 Contracts Remain Unaffected

Aave founder Stani Kulechov stated that the incident did not involve the core Aave V3 contracts.

“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said.

This means the exploit was linked to the custom automation layer rather than Aave V3’s main protocol contracts or liquidity pools.

Was this writing helpful?

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.