FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets

Bitbuy
Changelly



A custom FlashLoopAdapter used to manage leveraged Aave v3 positions has been exploited on Ethereum, leaving two Safe wallets with losses estimated at $305,000 after an attacker bypassed the module’s access controls.

Summary

  • A FlashLoopAdapter access control flaw allowed an attacker to drain around $305,000 from two Safe wallets on Ethereum.
  • The attacker used a Morpho flash loan to repay roughly 1,335 WETH in Aave debt before withdrawing about 1,306 weETH in collateral.
  • Aave founder Stani Kulechov said the affected contract was a third party adapter built on Aave and had zero effect on Aave v3.

Blockchain security firm SlowMist said the attacker exploited an authentication flaw in the FlashLoopAdapter contract, which allowed a fake Safe to pass checks meant to restrict access to wallets that had enabled the module. The attacker ultimately retained around 114.09 ETH after using the module to manipulate positions held by the affected wallets.

Binance

The incident involved a custom contract built on top of Aave rather than the core Aave v3 protocol. Defimon Alerts, which detected the attack at 15:08:57 UTC on Oct. 1, said Aave v3 itself was not affected.

FlashLoopAdapter access controls allowed a fake Safe to pass

FlashLoopAdapter was designed as a Safe module for opening and closing leveraged positions through Aave v3. Safes that enabled the module could use it to manage looping strategies involving borrowed assets and collateral.

According to SlowMist, the weakness was found in the access controls used by the adapter’s open() and close() functions.

Instead of independently establishing that the caller was a legitimate Safe, the functions checked whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true. An attacker could deploy a fake Safe contract programmed to return true when the FlashLoopAdapter made the check.

Once the fake Safe passed that test, the attacker gained access to functionality that should have been limited to authorized wallets.

Defimon Alerts said checks performed during the callback did not stop the transaction because the attacker’s contract acted as the flash liquidity provider as well. Another function, _swap(), then allowed a raw call to a swapRouter using caller supplied swapCalldata.

Both inputs could be controlled by the attacker.

Instead of providing an ordinary swap router, the attacker set the router to one of the victim Safe wallets. The calldata was set to call execTransactionFromModule, a Safe function that lets an enabled module execute a transaction.

FlashLoopAdapter was already enabled by the victim Safe, so the resulting call was accepted.

A similar problem involving permissions attached to Safe modules surfaced in September. An Ethereum Safe wallet exploit involving roughly 2,900 rsETH was traced by BlockSec to weak authorization checks in an executor contract connected to an enabled Safe module. An MEV bot front ran the attempted exploit and received the assets before the original attack transaction reverted, crypto.news previously reported.

Attacker repaid 1,335 WETH to unlock weETH collateral

The FlashLoopAdapter attack involved more than simply transferring assets already sitting inside the affected wallets.

Defimon Alerts said the attacker took a Morpho WETH flash loan and used the borrowed liquidity to repay approximately 1,335 WETH of Aave debt belonging to the first Safe, identified as 0xcfedf95a3653a128dfc2e4288758a1a1850d169f.

Repaying the debt freed collateral tied to the leveraged Aave position. The attacker then used the compromised module execution path to make the Safe withdraw approximately 1,306 weETH to an attacker controlled address.

A second Safe, 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520, lost another 6.4 weETH through the same vulnerable module.

Defimon said both affected Safes shared the same single owner.

Part of the withdrawn weETH was swapped into WETH as the attacker settled the flash loan and other parts of the transaction. The attacker was left with around 114.1 ETH, valued at approximately $305,000 when the incident was reported.

SlowMist separately put the loss at around 114.09 ETH and said roughly 1,300 WETH of debt was repaid during the process of unlocking the collateral.

The large collateral withdrawal therefore does not represent the attacker’s net proceeds. Much of the capital moved through the transaction was tied to repaying debt and unwinding the leveraged position before the remaining assets could be taken.

Aave v3 contracts were not identified as the vulnerable component

Neither security alert identified a flaw in Aave v3 itself.

Aave founder and CEO Stani Kulechov said the affected contract was a third party external adapter built on top of Aave and had “zero effect on Aave v3.”

FlashLoopAdapter is a separate custom contract that uses Aave v3 to manage leveraged positions held through Safe wallets. The reported vulnerability concerned how the adapter authenticated callers and what they could make the enabled module execute.

The distinction resembles other incidents in which a protocol or service remained operational while a module connected to Safe wallets provided the route used by an attacker.

In May, an exploit involving the SquidRouterModule drained Safes on Ethereum and Base. Around $3 million to $3.2 million was stolen from 86 wallets after attackers targeted a third party Safe module, while Squid said its main router contracts and user funds were unaffected.

Another Safe related incident emerged days later when users of Gnosis Pay were urged to withdraw funds following an exploit involving its Zodiac delay module. Gnosis co founder Martin Köppelmann said at the time that the flaw could let an attacker initiate transactions from Safes using the affected module.

Safe modules can be granted permission to execute transactions from a wallet without going through the standard owner transaction flow each time. FlashLoopAdapter relied on that capability to automate leveraged Aave positions, but the same permission meant a successful bypass of the adapter’s authentication logic could reach assets controlled by the Safe.

FlashLoopAdapter attacker retained around 114 ETH

SlowMist identified the attacker address as 0x42c2633438609881c8fBAb82414eb9A0c45F9353, while the vulnerable FlashLoopAdapter contract was listed as 0x16bb8b912da187870c23ec6756bb3fad061283d8.

The attack sequence combined the forged Safe authentication with control over the adapter’s router and calldata parameters. Once the malicious contract passed the initial check, the attacker directed the adapter back toward the victim Safe and invoked its module execution function.

A Morpho flash loan supplied the WETH needed to repay the larger wallet’s Aave debt before its weETH collateral could be removed. Approximately 1,306 weETH was withdrawn from that Safe, while another 6.4 weETH was taken from the second wallet.

After the borrowed liquidity was settled and part of the withdrawn assets was converted, Defimon Alerts calculated that the attacker retained approximately 114.1 ETH.

SlowMist classified the incident as a smart contract vulnerability and estimated the resulting loss at $305,000.





Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*