An attacker drained two Safe multisig wallets on Ethereum on October 1, 2026 by exploiting a third-party module called FlashLoopAdapter, designed to run leveraged positions on Aave v3. The attacker forged Safe authentication to repay approximately 1,300 to 1,335 WETH of Aave debt and unlock the victims’ collateral. Combined losses are estimated between $305K and $310K, with a net profit of roughly 114.09 ETH after repaying the flash loan sourced from Morpho. Neither Aave v3 nor Safe’s core infrastructure was compromised; the flaw resided entirely in the FlashLoopAdapter module, whose open() and close() functions poorly validated caller-supplied responses.
Source: Read the original article

