YFarmX logoYFarmX

Tools Crypto Exploit Tracker exploit-0144

Exploit record

Flaw in a Safe wallet add-on lets attacker take $307,000

Loss
$307k
Attack vector
Access Control
Chain
Ethereum
Sector
Wallet

What happened

At 15:08 UTC on 1 October 2026 an attacker abused FlashLoopAdapter, a custom Safe module that opens and closes leveraged Aave v3 loops, to drain two Safe wallets with the same owner. Using a Morpho flash loan, the attacker repaid one Safe's Aave debt, took the collateral it freed and a smaller amount from the second Safe, and kept 114.1 ETH, about $306,780.

Defimon and SlowMist agree on the root cause: the module's open() and close() functions trusted any caller that answered isModuleEnabled() as true, so a fake Safe passed the check, and its swap step then made a raw call to whatever router and calldata the caller supplied. The attacker pointed that call at the victim Safes' execTransactionFromModule, which the Safes ran because the module was enabled on them. The adapter is a custom contract built on top of Aave v3, and the flaw sits in the adapter, Defimon says. The loss values the 114.096 WETH the attacker unwrapped at Chainlink's ETH/USD price of $2,688.78 in the attack block; the flash loan also repaid about 1,335 WETH of Aave debt, about $3.59m at the same price. At 21:03 UTC on 1 October the address carrying the ENS name aavechan.eth, writing as the owners of the two Safes, sent the attacker an on-chain offer: keep 11.41 ETH, about $30,680, as a 10% bounty and return 102.69 ETH, about $276,110, before 18:00 UTC on 3 October.

On-chain references

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 2 October 2026