Third-party Aave adapter exploited; Aave says its core contracts were not affected

An attacker abused an access-check flaw in FlashLoopAdapter, an external contract for managing leveraged Aave v3 positions from Safe wallets, and took roughly 114 ETH from two wallets, Cointelegraph reports.

AI-generated illustration: chain of modules with one cracked external adapter and an intact vault
Illustration: ZUAS Network / AI-generated. A conceptual image; it does not depict the events described.

An attacker abused an access-check flaw in FlashLoopAdapter, an external contract for managing leveraged Aave v3 positions from Safe wallets, and took roughly 114 ETH from two wallets, Cointelegraph reports.

Security firm SlowMist and Aave’s founder say Aave v3 itself was unaffected.

This brief summarises the reporting by Cointelegraph (staff), published 2 October 2026. It is not original ZUAS Network reporting, and ZUAS Network has not independently verified the figures. Read the original for full details.

Sources

  1. Cointelegraph (staff) October 2, 2026
Companies: ,