Access-Control Vulnerability Exploited in FlashLoopAdapter
An access-control vulnerability in FlashLoopAdapter was exploited, leading to a loss of approximately $305,000. The attacker used a flash loan to drain weETH from two Safes.
The incident involved the FlashLoopAdapter, a component of the Aave V3 Loop Safe Module. An attacker exploited an access-control vulnerability by spoofing Safe authentication, which allowed them to bypass the module's authorization check. By manipulating the swapRouter and swapCalldata, the attacker executed unauthorized transactions targeting the victim Safes using the execTransactionFromModule() function.
To facilitate the attack, the perpetrator utilized a Morpho WETH flash loan to repay the affected Safe’s Aave V3 debt. This action unlocked the collateral held within the Safes, enabling the attacker to drain weETH from two Safes. The total loss incurred from this incident was approximately 114.09 ETH, valued at around $305,000.
The incident occurred on the Ethereum chain, which allows for tracking of the transactions involved. The on-chain record would reflect the unauthorized transactions executed by the attacker, detailing the flow of funds and the addresses involved in the exploit.
Addresses in this incident
| Address | Chain | Role | Check |
|---|---|---|---|
| 0x42c2633438609881c8fbab82414eb9a0c45f9353 | ETH | mentioned in coverage | Check live |
| 0x951ad21b85c1ce165f15d548a7c7d42520a32f1a | ETH | mentioned in coverage | Check live |
Roles are attributed to the source that stated them. Addresses without an attributed role are listed because coverage mentioned them, not because we assign them a part in the incident.
