A customized FlashLoopAdapter used to handle leveraged Aave V3 positions was exploited in a hack on Ethereum, leaving two Secure wallets with an estimated web lack of 114.09 ETH, or about $305,000.
The attacker spoofed a Secure authentication verify, then used a Morpho WETH flash mortgage to repay debt and unlock collateral. The roughly 1,306 weETH withdrawn from one pockets was a gross transaction movement, not the attacker’s web proceeds.
SlowMist: Aave v3 Loop Secure Module Exploited, Roughly 114.09 ETH Stolen
SlowMist issued a safety alert stating that Aave v3 Loop Secure Module was exploited by means of an access-control vulnerability in FlashLoopAdapter’s open() and shut() capabilities. The attacker allegedly… pic.twitter.com/a97iMcGWnI— Wu Blockchain (@WuBlockchain) October 2, 2026
Defimon Alerts stated it detected the Ethereum assault at 15:08:57 UTC on Thursday, October 1. SlowMist revealed its evaluation on Friday, October 2, figuring out a weak point within the adapter’s open and shut capabilities. A malicious contract may pose as a Secure and return that worth, passing a verify supposed to verify {that a} respectable pockets had enabled FlashLoopAdapter.
The AAVE hack attacker-controlled contract additionally equipped the adapter’s swap router and calldata. It pointed the router at a sufferer Secure and set the calldata to invoke execTransactionFromModule. As a result of FlashLoopAdapter was already enabled on that Secure, the pockets accepted the decision as a licensed module transaction.
The sequence turned a slim authentication flaw into entry to wallet-controlled collateral. The episode underscores how pockets permissions and execution paths matter alongside the safety of the lending protocol itself, a priority additionally central to custody infrastructure and authentication controls.
Earn $50 and Enter $300K Prize Draw on EdgeX
Flash Mortgage Hack Repaid Aave Debt Earlier than Collateral Was Withdrawn
Aave (AAVE)24h7d30d1yAll time
The attacker used a Morpho flash mortgage denominated in WETH to repay roughly 1,335 WETH of Aave debt related to the bigger Secure. Compensation freed collateral tied to its leveraged place, permitting roughly 1,306 weETH to be withdrawn. A second Secure misplaced about 6.4 weETH by means of the identical susceptible module.
Each affected Safes had the identical single proprietor. After the borrowed funds have been settled and a few belongings transformed, the attacker retained roughly 114.09 ETH, which safety experiences valued at about $305,000.
The excellence between gross motion and realized loss is materials. The big collateral withdrawal enabled the debt reimbursement and place unwind; it shouldn’t be learn as the quantity stolen. The reported web proceeds have been the ETH remaining after these transaction steps.
Commerce AAVE on Bybit and Get a Likelihood to Win Our $1,000 USDT Airdrop
Aave Says Core Contracts Not Affected
Aave founder and CEO Stani Kulechov stated the susceptible part was an exterior integration reasonably than an Aave V3 contract and had “zero impact on Aave v3.”
This isn’t Aave v3 contract, it’s third occasion exterior adapter constructed on high of Aave, zero impact on Aave v3.
— Stani (@StaniKulechov) October 2, 2026
SlowMist labeled the incident as a smart-contract vulnerability and attributed the bypass to the spoofable Secure verify. Defimon described FlashLoopAdapter as a Secure module for opening and shutting leveraged Aave V3 loops and estimated the loss at roughly $305,000.
FlashLoopAdapter is a customized contract constructed on Aave V3 for managing leveraged positions in Safes that enabled it. Secure modules can execute pockets transactions with out requiring the usual proprietor transaction movement every time, which helps automation but additionally provides a licensed module a path to pockets belongings.
Right here, the module’s permission was not itself the reported bug; the adapter’s caller-authentication and execution logic have been. The case is subsequently a DeFi safety failure on the integration layer, not proof that Aave V3’s lending swimming pools have been compromised.
The first supply additionally notes a separate September Secure-wallet incident involving roughly 2,900 rsETH and weak authorization in an executor related to an enabled module, however the two incidents concerned distinct contracts and assault paths.
Uncover: The Finest Token Presales
The publish Two Secure Wallets Lose $305,000 in FlashLoopAdapter Assault appeared first on Cryptonews.