Skip to content

Invest2 publishers2 min readPublished Updated

Attacker drains up to $310K from two Safes through a leverage module the owners switched on

Two Safe multisigs lost up to $310K after an attacker impersonated a Safe to get past FlashLoopAdapter, an Aave leverage add-on the owners had enabled. Aave and Safe's core code held, so the loss fell on owners who let a module move funds without signatures.

The Investor · Invest desk

Illustration accompanying Attacker drains up to $310K from two Safes through a leverage module the owners switched on

What happened

  • Funded by a Morpho flash loan inside a single transaction, the attacker paid down roughly 1,300 to 1,335 WETH of the wallets' Aave debt to free their collateral.
  • Collateral worth around 1,306.48 WETH came out of one Safe and a smaller sum from the other, leaving the attacker about 114.09 ETH after repaying the loan.
  • Security firms SlowMist and ExVul raised alerts, and both affected Safes disabled the module right away to stop further losses.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure A leveraged Safe position is only as strong as the least-audited contract allowed to touch it, so each module that can move funds needs at least the review its signer set gets.
  • decision With FlashLoopAdapter switched off, both owners are back to running every leverage step by hand through their signers, the work the module was enabled to spare them.
  • capability Because borrowed WETH covered more than 1,300 WETH of debt for one transaction, a similar adapter bug can be exploited by someone without capital of their own, up to the size of the victim's position.

Set the attacker's net of about 114.09 ETH [10] against the roughly 1,300 to 1,335 WETH of Aave debt it had to repay first [8], and the take is 8.5% to 8.8% of the borrowing it cleared [1]. Put the other way, about 11.4 to 11.7 ether of debt sat behind every ether the attacker kept [2]. These were thin positions, the kind a module like FlashLoopAdapter is built to assemble [5].

The victims' loss is the same gap seen from their side. Their debt was repaid in the same transaction that took their collateral [8], so what they lost is the equity between the two. Divide Crypto Briefing's $305K to $310K loss estimate [3] by 114.09 ETH [10] and you get about $2,670 to $2,720 per ether [3]. At that price the dollar figure and the attacker's net are the same sum. The report does not say what ether price it used.

The fault can sit in one of three places. The narrow answer is a single badly written adapter. Post-incident analyses cited by Crypto Briefing found that open() and close() accepted caller-controlled responses without confirming they came from a legitimate Safe [11]. According to SlowMist's account, a fake contract posing as Safe authentication got past that check [6][2]. The broad answer is Safe's design. A module with broad execution rights inherits the wallet's power, and the multisig's signature requirements do little once the module has been granted a way around them [13]. The third answer blames the flash loan for supplying the capital [15], though the borrowed WETH only mattered after the adapter had let the wrong caller in [11].

I think the narrow answer fits the evidence. The broad one is the counter-thesis that anyone holding leveraged Safe positions should keep in mind anyway. Aave released collateral because debt was repaid, as designed [14]. But the owners had given the adapter permission to operate their accounts [5], so along its code paths their multisig was protected only by the checks the adapter's authors wrote [13]. The narrow answer would be wrong if a later analysis traced the forged authentication past a check in Safe's own contracts. The analyses so far put the failed check inside FlashLoopAdapter [11][14].

What to watch

  • Where the attacker's roughly 114.09 ETH goes next; a freeze or return would shrink the victims' $305K to $310K loss.
  • Whether other Aave leverage adapters for Safe turn out to accept a caller's claim to be a Safe in the same way open() and close() did.
  • Any change by Safe to how enabled modules can execute without signer approval, a move that would put part of the fault in the core design.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories