A Flash Adapter Cost Two Safe Wallets $305K. Here's Who's Actually Exposed
An attacker spoofed a Safe authentication check and drained a custom FlashLoopAdapter on Ethereum, leaving two wallets down 114.09 ETH. Safe's multisig held. Aave's core contracts held. The glue between them didn't.
Safe didn't get hacked. Neither did Aave. Somebody's custom adapter did, and it cost two wallets 114.09 ETH, about $305,000.
That distinction matters way more than the dollar figure. Because if you're running any kind of custom contract on top of a battle-tested protocol, this one's aimed straight at you.
The Setup
Here's what went down on Ethereum. A contract called FlashLoopAdapter, built to manage borrowed positions on Aave V3, got exploited. The attacker spoofed a Safe authentication check to slip past the guard rails, then fired a Morpho WETH flash loan to repay debt and unlock the collateral sitting behind it.
Once that collateral was free, roughly 1,306 weETH walked out the door. Net damage: 114.09 ETH across two Safe wallets.
Read that again. The attacker didn't crack Safe's multisig. They didn't find a bug in Aave's lending pool. They found a hole in the glue between them.
This is the pattern now. The big protocols have been hammered on for years and they've mostly held. So attackers moved down the stack to the custom stuff. The adapters. The routers. The wrappers. The loopers. The code somebody wrote in a weekend to make a position slightly more efficient.
The Counterpoint
Aave's team was quick to say its core contracts were unaffected. And they're right. That's a real point in their favor.
But "core contracts are fine" is doing a lot of heavy lifting here. The entire reason you build a FlashLoopAdapter is to interact with Aave. If users get drained through a tool pointed at your protocol, saying the protocol itself is untouched is technically true and practically cold comfort.
Then again, maybe that's unfair. DeFi composability means anyone can permissionlessly write a contract that talks to Aave. You can't audit the whole world. Safe didn't build the adapter. Aave didn't build the adapter. Somebody else did, and two people trusted it with real money.
So who's at fault? Probably whoever deployed unaudited custom code and pointed it at a six-figure position. Harsh, but that's the game.
The Verdict
This wasn't a Safe failure or an Aave failure. It was a custom-code failure, and those keep happening because almost nobody is watching the middle layer.
Traders are watching closely, and they should be. Because the lesson isn't "avoid Safe" or "avoid Aave." The lesson is that every custom contract in your stack is a trust assumption, and most people never bother counting them.
Want a number? $305,000 was the price of two wallets not counting theirs.
What to watch next: whether these adapter-style contracts get audited or just quietly abandoned. And whether Aave and Safe start publishing real guidance on third-party tooling. Because right now, the space between two solid protocols is exactly where the money's getting taken.
Here's the thing. Your multisig is only as safe as the worst contract you let touch it.
Related Articles
Explore More
Key Terms Explained
One of the biggest lending and borrowing protocols in DeFi.
Assets you put up as security when borrowing.
The ability to combine different DeFi protocols like building blocks to create new financial products.
A blockchain platform that enabled smart contracts and decentralized applications.