Safe Wallets Lose $305K in Adapter Attack

Attack exploited a third-party Aave v3 adapter, with no impact on the core protocol

Safe Wallets Lose $305K in Adapter Attack

Third-Party Adapter Breach Costs Safe Wallets $305,000

An attacker drained approximately $305,000 from two Safe multisig wallets by exploiting a third-party adapter built on Aave v3, though the core lending protocol remained unaffected. Aave founder Stani Kulechov clarified that the compromised component was an external adapter rather than the Aave v3 contract itself, resulting in zero impact to the protocol.

SlowMist identified the attack vector as a module designed for managing leveraged Aave v3 positions through Safe wallets. A flawed authorization check enabled the attacker to present a counterfeit Safe contract that the adapter accepted as legitimate. The adapter's design also granted the caller control over routing and swap transaction data, which the attacker leveraged to execute unauthorized transactions through the compromised Safes.

The attacker repaid roughly 1,300 WETH in outstanding debt to release locked collateral, then extracted approximately 114.09 ETH—valued at around $305,000—from the two multisig wallets. SlowMist traced the vulnerable FlashLoopAdapter contract and the attacker's address, confirming that Aave v3 sustained no direct losses from the incident.

Hot Stories

Submit an application

Leave a request

How to contact you?

Specify Telegram username or email — depending on the chosen method of communication.