$300K Gone in a Flash: Aave-Connected Wallets Just Got Drained and Nobody Saw It Coming

Two Safe multisig wallets were silently drained of 114 ETH, over $300,000, through a vulnerability hiding inside a third-party tool built on top of Aave, and most of the DeFi world didn't even notice it happened.

What Actually Went Wrong

On October 2, blockchain security firm SlowMist confirmed the attack was not a flaw in Aave itself. The protocol survived untouched. The real problem was buried inside the FlashLoopAdapter, a lending adapter built by a third party to interact with Aave v3 positions.

That adapter had a critical flaw. The attacker found it, exploited it, and used it to compromise the two Safe multisig wallets before anyone could respond. The funds were gone fast.

This is the part that should keep DeFi users up at night: Aave's code worked exactly as intended. The exploit lived in the layer between the user and the protocol, a third-party integration that most users probably didn't even know existed in their stack.

Why This Is Bigger Than the Number Suggests

$300,000 is not a record-breaking hack. But the attack surface it exposes is enormous.

DeFi has spent years hardening core protocols. Aave, Uniswap, Compound, the big names have been audited, battle-tested, and patched repeatedly. But the ecosystem around them, the adapters, wrappers, routers, and automation tools built on top, those are a different story. They often move fast, audit light, and carry real user funds.

Safe multisig wallets are widely considered one of the most secure ways to hold crypto. The fact that two of them were drained through a peripheral tool should be a loud signal to every DAO treasury, DeFi power user, and protocol team using any third-party integration on top of a major lending protocol.

What You Should Do Right Now

If you are actively using any third-party adapter, automation tool, or custom integration layered on top of Aave v3, or any other DeFi lending protocol, this is not the moment to assume you are safe because the core protocol has a clean track record.

Check your integrations. Know what is touching your wallet. Verify that any tool in your stack has been audited by a reputable firm and that the audit is recent. If you cannot answer those questions confidently, consider revoking approvals until you can.

SlowMist's rapid identification of this exploit is a reminder that on-chain forensics are getting sharper. But faster detection does not recover lost funds.

Watch for any follow-up disclosure from the FlashLoopAdapter team. If a patch is not already live, the attack surface may still be open.