Skip to main content
Back to news
Safety

Two Safe Wallets Lose $305,000 in FlashLoopAdapter Exploit

(10 hours ago) · 1 source · Summarized by CryptoBipto — how we make this

Two Safe multisig wallets reportedly lost a combined $305,000 in an attack exploiting a vulnerability in the FlashLoopAdapter contract. The exploit appears to be connected to the Aave ecosystem. Details about the attacker and the full scope of the vulnerability are still emerging.

WHY IT MATTERS

In crypto, when you use a decentralized finance (DeFi) application, you often give that application permission to move your tokens on your behalf — this is called a "token approval." Think of it like giving a contractor a key to your house so they can do renovations. If that contractor turns out to be untrustworthy, or if someone steals their key, your house is at risk. In this case, the FlashLoopAdapter contract — a tool designed to automate certain lending strategies — had a vulnerability that an attacker exploited to drain funds. Even though the wallets themselves (Safe wallets) are considered secure, the permissions the owners had granted to this external contract created an opening. This incident highlights why it is important for crypto users to regularly review which contracts they have approved to access their funds and to revoke permissions they no longer need.

According to reports, an attacker exploited a vulnerability in a contract known as FlashLoopAdapter to drain approximately $305,000 from two Safe (formerly Gnosis Safe) multisig wallets.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

RELATED

AAVEDeFi SecuritySmart Contract ExploitsFlash LoansWallet Security