The exploit broke nothing that was supposed to hold. Aave v3 stood intact. Safe's core contracts stood intact. What failed was quieter — a trust check that was never a trust check at all. Over a span of hours, an attacker drained 114 ETH, roughly $300,000, from two Safe multisig wallets by deploying a counterfeit contract that answered every question it was asked with the same single word: yes. No oracle manipulation. No flash loan. No governance capture. Just a fake that lied consistently to an adapter that never verified who it was talking to. The vulnerabilities that empty wallets are rarely the ones audits are written to find; they are the ones everyone assumed were already solved.

For context, the compromised component was not Aave itself but FlashLoopAdapter, a third-party middleware built on top of Aave v3 to automate loop strategies — the recursive borrow-and-redeposit dance that magnifies yield and, with it, risk — for users of Safe multisig wallets. Safe's module system lets an external contract be enabled as a "module" with the authority to execute transactions on the wallet's behalf. The adapter was one such module. According to SlowMist's technical disclosure, it was a wrapper rather than a protocol innovation: integration-layer code running live on mainnet, with no public evidence of an independent audit. Aave founder Stani Kulechov moved quickly to clarify that the Aave v3 core contracts were unaffected, and on the numbers he is almost certainly right. Aave sits on more than $33 billion in total value locked. A $300,000 loss against that base is 0.0009% — statistically invisible, economically irrelevant. Zoom out, and this is the same structural story macro watchers have tracked all cycle: capital crowds into yield-bearing instruments faster than the risk frameworks around them mature. The composability layer is the newest place that gap hides.
Two classic defects stacked into one exploit. The first is authentication forgery, a confused-deputy pattern in its purest form. The adapter's open() and close() functions authorized callers by asking the calling Safe whether the adapter had been enabled as a module. But the caller supplies its own Safe address. The attacker deployed a counterfeit Safe that returned true to that query unconditionally, and the adapter — trusting an input it did not control — waved it through.
The second defect is the arbitrary external call. The adapter let the caller specify both the router address and the calldata. The attacker pointed the router at the victim's real Safe and set the calldata to execTransactionFromModule — the privileged entry point Safe grants to enabled modules.
Reconstructed, the chain reads like this:
attacker -> adapter.open() -> fake Safe satisfies auth check -> adapter executes external call (router = victim Safe, calldata = execTransactionFromModule) -> victim Safe trusts the adapter as its own module -> arbitrary transaction executes -> weETH and collateral transferred out
Based on my own audit experience tracing recursive-call structures back in the 2017 ICO cycle — where I broke down the TheDAO failure not as negligence but as a structural flaw in how calls re-entered each other — this is a textbook confusion of identity and authority. The adapter never asked "are you who you claim to be." It asked "do you say yes," and a counterfeit was happy to oblige.
Two inferences follow that the disclosure does not state outright but the mechanics imply. First, the adapter's authentication path almost certainly never faced an independent audit, or an auditor would have flagged a check that trusts caller-supplied input — this is not subtle once you look at it. Second, allowing a caller to name both the router and the calldata is an anti-pattern, and anti-patterns in DeFi tend to be copy-pasted. If the same code shape lives in sibling adapters, the exposure is not two wallets; it is every multisig that ever enabled a similar module. The attacker's modest 114 ETH target hints at a probe rather than a ceiling — a proof of concept, or simply a shallow pool, not a limit on capability.
The stolen collateral is telling. The victim positions held weETH, Ether.fi's restaked ETH receipt, alongside WETH. That is a re-staking loop: a yield-bearing derivative posted as collateral, borrowed against, redeposited, borrowed again. Such positions are already fragile — they break if restaking yields compress or if weETH depegs — and the exploit simply layered contract risk on top of depeg risk on top of integration risk. When restaking incentives were rich, nobody questioned the wrapper. When they thin, the wrapper is exactly what gets tested — and this wrapper failed before the yield even had a chance to. Stacked leverage does not compound returns so much as it compounds the number of ways a position can fail.
Here the composability that DeFi celebrates as its defining virtue became the attack surface. Aave's core remained sound. The integration built around it did not. As the disclosure put it, protocol security can stay intact while the integrations around it manufacture an independent attack vector.
The reflexive read is that this is an Aave problem. It is not, and the instinct to assign blame to the largest name in the frame is precisely the error that keeps repeating. Aave did not fail; the ecosystem's habit of treating "built on Aave" as synonymous with "as safe as Aave" failed. That equivalence was never true. It was a narrative, and narratives are where capital gets mispriced.
Systemic risk hides where the charts are too clean — and a $300,000 loss leaves no mark on any chart. That cleanliness is the danger. The disclosure raises the question the market will not price: how many other wallets enabled the same module? If the adapter is an open template, forked and redeployed by other teams, then 114 ETH is not the loss — it is the first loss. Institutions smell blood when retail smells profit, and the institutional read here is not the price of AAVE; it is the audit trail of every third-party wrapper sitting silently inside a multisig.
Kulechov's separation of core from integration is technically sound and strategically motivated at once. A founder has every incentive to contain a narrative, and "zero impact on Aave v3" protects the brand even as it sidesteps the composability question. The signal is weak; the noise is deafening.
What matters now is not the 114 ETH. It is whether the same authentication forgery recurs across unpatched adapters before anyone bothers to enumerate them. The discipline this demands is unglamorous: treat every third-party wrapper as untrusted until its audit proves otherwise, and treat "based on Aave" as a starting point for scrutiny rather than a substitute for it. The next loss will not announce itself through a headline. It will announce itself through a query that returned yes when it should have returned no.