
Third-party Aave v3 module compromised by falsifiable access control
Security firm SlowMist reports the exploitation of FlashLoopAdapter, a third-party module of Aave v3, resulting in the loss of 114.09 ETH on two Safe multisignature vaults due to tampering access control.
AI-generated summary
The company SlowMist reported the exploitation of a flaw in FlashLoopAdapter, a third-party module linked to Aave v3.
A sham access control. Security firm SlowMist reported exploitation of FlashLoopAdapter, a custom Safe module designed to manage leveraged positions on Aave v3. The attacker combined tamperable access control with an overly permissive swap function to empty two multisignature vaults.
The net loss reached around 114.09 ETH. Over 1,300 WETH borrowed on Aave v3 was also repaid to free up collateral. The Aave v3 protocol itself has not been compromised. Here's what we know.
Key Points
The incident concerns FlashLoopAdapter, a third-party module installed on two Safe wallets
Access control could be fooled by a fake contract posing as a Safe wallet
The attacker also controlled the router and the data used by the module's exchange function
Aave v3 markets suffered no losses: the flaw was in an external integration layer
Aave v3 intact, FlashLoopAdapter trapped by a fake Safe
FlashLoopAdapter was used to open or close so-called looping positions in a single transaction. This strategy involves posting an asset as collateral, borrowing WETH, and then redepositing the resulting funds to amplify exposure to yield and potential rewards.
Contrary to a first reading of the code, the open() and close() functions did have access control. The contract verified that the caller was a Safe wallet that had FlashLoopAdapter enabled as a module. However, this verification was based on the response provided by the caller himself.
The attacker therefore deployed a false contract capable of presenting itself as Safe and systematically responding that the module was authorized. This first circumvention, however, was not enough to empty the targeted wallets.
The second weakness was in the internal _swap() function. This let the user freely provide the address of the exchange router and the associated call data. The attacker could thus direct the module towards a contract of his choice and make it execute arbitrary instructions.
FlashLoopAdapter was already legitimately activated on both victim Safes. He therefore had the right to use execTransactionFromModule, a function that allows an approved module to execute a transaction without recollecting the usual signatures of the multisignature wallet.
Two Safe Vaults Lose 114 ETH, Flawless in Aave
To recover the collateral, mainly composed of weETH, the attacker had to first settle the loans taken out on Aave. He used a flash loan, that is to say a loan obtained and repaid within the same transaction, to repay more than 1,300 WETH of debt and unlock the assets deposited as collateral.
After repaying the instant loan and paying the fees, the net profit of the operation reached approximately 114.09 ETH. This sum corresponds to the remaining value of the positions which should have gone to the owners of the two vaults.
Neither Aave v3 nor Safe core contracts had the exploited vulnerability. The loss comes from a third-party module to which the owners had voluntarily granted extended rights. SlowMist does not specify which team developed or deployed this adapter.

The Ethena protocol diversifies its stablecoin USDe by integrating tokenized American stocks (bStocks) on Binance. This strategy aims to decorrelate the 'basis trade' returns from crypto assets alone, with open interest exceeding $2.9 billion.

Bitcoin digests the bond market this September 27 while Zcash, Chainlink and Cardano test key resistances. Conversely, Hyperliquid's HYPE token fell after its listing on Binance following profit-taking.

Bitcoin falls to around $84,000 under pressure from the yield on 10-year US Treasury bonds, which has risen above 5%, while bitcoin ETFs record a record weekly inflow of $2.4 billion, the strongest in a year.

Bitcoin falls back to around $84,000 after $15.6 billion of options on Deribit expired, erasing its rebound above $85,000. US bitcoin ETFs record seven consecutive days of positive flows, while sources speak of a possible resumption of US strikes in Iran after the mid-term elections.

The rise in US ten-year bond yields immediately penalizes bitcoin by making risk-free assets more attractive, but this same rise, when it arises from concerns over US debt, strengthens the monetary argument of BTC advocates as an alternative to an inflationary currency.

Ondo is up 24-29% after the launch of three tokenized wallets developed with BlackRock, while Quant, Litecoin, Ethena and Algorand also see double-digit increases. Large caps like Ethereum, Solana or BNB remain stable, preventing a widespread altseason despite the rotation towards certain sectors like tokenized real assets, interoperability and artificial intelligence.