Market Cap: $2.9256T 1.33%
Volume(24h): $103.1186B 3.45%
  • Market Cap: $2.9256T 1.33%
  • Volume(24h): $103.1186B 3.45%
  • Fear & Greed Index:
  • Market Cap: $2.9256T 1.33%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$85928.023813 USD

2.27%

ethereum
ethereum

$2729.934063 USD

0.64%

tether
tether

$0.999614 USD

0.02%

bnb
bnb

$777.040634 USD

0.86%

xrp
xrp

$1.523805 USD

1.33%

usd-coin
usd-coin

$0.999921 USD

0.02%

solana
solana

$121.557757 USD

2.05%

tron
tron

$0.334134 USD

-0.98%

zcash
zcash

$1378.204660 USD

-4.34%

hyperliquid
hyperliquid

$90.088533 USD

0.86%

dogecoin
dogecoin

$0.095878 USD

0.15%

chainlink
chainlink

$14.394223 USD

-0.36%

monero
monero

$549.044846 USD

-0.25%

cardano
cardano

$0.254373 USD

0.44%

unus-sed-leo
unus-sed-leo

$8.969563 USD

1.40%

Cryptocurrency News Articles

SlowMist Uncovers FlashLoopAdapter Flaw Draining Safe Wallets: A Wake-Up Call for DeFi Integrations

Oct 03, 2026 at 08:05 am

SlowMist has reported a critical vulnerability in FlashLoopAdapter, a third-party Aave integration, leading to 114 ETH being drained from two Safe multisig wallets. This incident highlights the inherent risks in external DeFi modules, even with robust core protocols like Safe.

SlowMist Uncovers FlashLoopAdapter Flaw Draining Safe Wallets: A Wake-Up Call for DeFi Integrations

In the ever-evolving landscape of decentralized finance (DeFi), security is paramount, yet a recent incident brought to light by blockchain security firm SlowMist serves as a stark reminder that even the most fortified systems can be vulnerable through their external connections. A flaw in a third-party integration, dubbed FlashLoopAdapter, allowed an attacker to siphon approximately 114 ETH (valued around $305,000 at the time of reporting) from two Safe multisig wallets.

The Achilles' Heel: FlashLoopAdapter's Access Control

SlowMist's investigation pinpointed FlashLoopAdapter as the weak link. This component, designed to manage leveraged Aave v3 positions, was an external adapter, not a core part of the Safe multisig wallet protocol or the Aave v3 itself. This distinction is crucial: the core Safe contracts remained uncompromised. The vulnerability lay in FlashLoopAdapter's access control mechanisms for its open() and close() functions. These functions merely checked if a module was enabled by calling ISafe(msg.sender).isModuleEnabled(address(this)), a check that was unfortunately spoofable.

The attacker cleverly exploited this by deploying a fake Safe contract that would always return 'true' to this module enablement query. Furthermore, the _swap() function within FlashLoopAdapter allowed the caller to dictate the swap router and its data. The attacker leveraged this to set the router to one of the victim Safe wallets and then, through the execTransactionFromModule function (a legitimate Safe function for enabled modules), executed unauthorized transactions. The consequence? Collateral locked in Aave v3 positions via FlashLoopAdapter was drained.

A Pattern of Peripheral Vulnerabilities

This isn't SlowMist's first rodeo in identifying vulnerabilities stemming from peripheral integrations. The firm has a consistent track record of tracing significant losses back to adjacent components rather than core protocols. This incident echoes previous findings, such as the Liquid Network exploit that minted 3,998 L-BTC, where a similar attack vector bypassed core defenses through an external module. These cases collectively underscore a critical trend: while core protocols may be robust, the security perimeter often expands with every third-party integration.

The Broader Implications for Safe Wallets and DeFi

Safe wallets are widely celebrated for their enhanced security in DeFi, particularly through their multisig capabilities. However, the FlashLoopAdapter incident highlights a fundamental truth: security is only as strong as its weakest link. When users grant third-party adapters interaction privileges with their wallets, these adapters inherit significant execution power. A flaw in the adapter's logic, even if the wallet itself functions perfectly, can be weaponized.

This serves as a potent reminder for anyone engaging with DeFi strategies that involve external modules. Authorizing an adapter is not a trivial decision; it entails trusting the adapter's code as much as, if not more than, the core protocol. The true blast radius of this exploit—how many other wallets had authorized FlashLoopAdapter before the flaw was discovered—remains an open question, underscoring the ongoing challenge of securing the interconnected DeFi ecosystem.

Looking Ahead: A Call for Scrutiny and Enhanced Vigilance

While the attacker's identity remains unknown and remediation steps are not publicly detailed, this incident provides valuable lessons. It's a clear call for increased scrutiny of third-party integrations and robust access control mechanisms. As DeFi continues to innovate, the onus is on both developers and users to prioritize comprehensive security audits and understand the full implications of every integration. In the end, staying safe in the digital frontier often comes down to paying attention to the fine print—and the code behind it. Let's keep those wallets safe and sound, one secure integration at a time!

Original source:coinmarketcap

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Oct 03, 2026