NewsCryptoSlowMist: FlashLoopAdapter Vulnerability Drained Collateral From Two Safe Multisig Wallets

SlowMist: FlashLoopAdapter Vulnerability Drained Collateral From Two Safe Multisig Wallets

Author: CoinWy·

Key Takeaways

  • •The collateral drain originated from a flaw in the third-party FlashLoopAdapter, not from Safe's core contracts.
  • •Two separate Safe multisig wallets were targeted by the attacker, indicating the flaw could affect any wallet that authorized the adapter.
  • •Once enabled as a Safe module, the adapter could initiate transactions with the wallet's own authority, exposing protected collateral through its code path.
  • •The incident follows a similar earlier exploit SlowMist documented, the Aave v3 Loop Safe Module case involving 114.09 ETH, suggesting the adapter-level risk pattern has recurred.
  • •Specific loss figures, transaction hashes, and owner identities have not been released, so the full scope of the incident remains unverified pending SlowMist's complete disclosure.
SlowMist: FlashLoopAdapter Vulnerability Drained Collateral From Two Safe Multisig Wallets

Blockchain security firm SlowMist has reported that a vulnerability in a third-party component known as FlashLoopAdapter allowed an attacker to drain collateral from two Safe multisig wallets, raising renewed concerns about the risks that external adapters can introduce into otherwise hardened custody setups.

Flaw Located in Third-Party Adapter, Not Safe Core Contracts

According to SlowMist, the exploit originated in the FlashLoopAdapter, a third-party module integrated alongside Safe multisig wallets, rather than in a weakness of the Safe protocol itself. The firm attributed the collateral drain directly to a flaw in that adapter, not to Safe's core contracts.

The distinction is significant because Safe, the multisig wallet framework formerly known as Gnosis Safe, is widely used across DeFi, and conflating the adapter with the core protocol would misrepresent the scope of the incident.

The report also follows a pattern SlowMist has documented before. In a prior alert covering the Aave v3 Loop Safe Module exploit involving 114.09 ETH, the firm described how loop-based flash loan strategies integrated through Safe modules could expose user collateral to attack. The FlashLoopAdapter incident appears to fall within that same category of adapter-level risk.

Loop adapters in this category automate a flash loan strategy that repeatedly cycles borrowed funds through a lending position, concentrating the entire operation in a single contract. That concentration is what turns a defect in the adapter's logic into direct exposure for the collateral a wallet holds.

How Two Safe Multisig Wallets Lost Collateral

The attacker targeted two separate Safe multisig wallets and drained collateral from both. Safe multisig wallets, which require multiple private-key signatures to authorize transactions, are a common choice for DeFi users and DAOs seeking stronger security guarantees than a single-key wallet can provide.

The incident demonstrates that the multisig structure itself does not protect against exploits that operate through an authorized but vulnerable module or adapter.

The mechanism follows from Safe's modular design: wallet owners can enable external modules that are granted standing authority to initiate transactions through the wallet, and strategy adapters such as FlashLoopAdapter are typically wired in as exactly this kind of module. Once a module is authorized, transactions routed through it execute with the wallet's own authority, so the collateral the multisig protects becomes reachable through the module's code path.

SlowMist has not disclosed the specific token amounts lost, the transaction hashes, or the identities of the wallet owners in available reporting. Without on-chain confirmation of those details, no dollar figure can be assigned to the loss. Readers seeking verified on-chain data should monitor SlowMist's official disclosures and cross-reference any transaction claims against Etherscan once full details are published.

Why the Incident Matters for Safe Wallet Users

The core lesson is dependency risk. A Safe wallet's security model is only as strong as the modules and adapters authorized to interact with it. A third-party adapter that has not been rigorously audited can introduce attack surface even when the underlying Safe contracts are sound.

Module-level exploits of this kind are not theoretical. The Aave v3 Loop Safe Module case that SlowMist previously flagged involved 114.09 ETH and demonstrated that looping strategies executed through Safe modules can be manipulated when adapter logic contains flaws. The FlashLoopAdapter incident suggests the pattern has recurred with a different adapter targeting the same architectural weakness.

Key Takeaways

  • Third-party adapters carry independent risk. Vetting the Safe protocol is not sufficient if attached modules have not been separately audited.
  • Two wallets were affected. The incident was not isolated to a single user, suggesting the flaw was exploitable across any Safe wallet that had authorized the FlashLoopAdapter.
  • Wait for SlowMist's full disclosure. Specific loss figures and transaction details have not been independently verified at publication. Rely on SlowMist's official post-mortem before drawing conclusions about scope.

Until SlowMist publishes a complete incident report with transaction-level evidence, the full scale of the FlashLoopAdapter exploit remains unconfirmed. Safe wallet users who have authorized any flash loan or loop adapter should review their module permissions and consult SlowMist's advisories for remediation guidance.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.