NewsCryptoSlowMist: FlashLoopAdapter Flaw Drains Collateral From Two Safe Multisig Wallets

SlowMist: FlashLoopAdapter Flaw Drains Collateral From Two Safe Multisig Wallets

Author: DefiLiban·

Key Takeaways

  • •SlowMist traced the incident to a flaw in FlashLoopAdapter, a third-party component, rather than a vulnerability in Safe's core contracts or signing logic.
  • •An attacker reportedly leveraged the adapter flaw to extract collateral from two distinct Safe multisig wallets that had integrated the component.
  • •The current disclosure lacks confirmed loss figures, transaction hashes, attacker addresses, and a verified adapter-level root cause, with all claims attributed solely to SlowMist.
  • •A previous exploit involving a looping module connected to Safe wallets, the Aave v3 Loop Safe Module incident, led to 114.09 ETH being stolen, indicating loop-style adapters are a recurring attack surface.
  • •Adapters holding delegated execution rights can move wallet funds without passing through the multisig signing workflow, so teams should review and revoke unused adapter permissions as standard operational security.
SlowMist: FlashLoopAdapter Flaw Drains Collateral From Two Safe Multisig Wallets

Blockchain security firm SlowMist has identified a flaw in FlashAdapter, a third-party component that reportedly allowed an attacker to drain collateral from two Safe multisig wallets. The finding highlights a class of integration risk that sits outside the core multisig controls Safe provides, raising questions about how teams vet the adapters and modules they connect to their wallets. Safe, formerly known as Gnosis Safe, is widely used across DeFi for treasury management, making flaws in connected components a concern that extends beyond the directly affected wallets.

Key Points

  • SlowMist attributed the incident to a flaw in FlashLoopAdapter, a third-party adapter — not a vulnerability in Safe itself.
  • An attacker exploited the flaw to drain collateral from two separate Safe multisig wallets.
  • The reported impact was collateral loss; no confirmed loss figures, transaction hashes, or attacker addresses are available in the current disclosure.

What SlowMist Reported

According to SlowMist, the vulnerability resided in FlashLoopAdapter, which is described as a third-party adapter rather than a native Safe contract. The flaw gave an attacker a path to extract collateral from two wallets that had integrated the component, while's multisig signing logic remained intact.

That distinction matters because it shifts the attack surface away from Safe's well-audited core and toward a peripheral integration point. SlowMist attributed collateral drainage as the reported impact, but the full technical root cause — including any specific call paths, re-entrancy vectors, or access control failures — has not been confirmed in the current disclosure. All incident claims are attributed solely to SlowMist's reported findings. Those unconfirmed elements — precise loss figures, transaction hashes, attacker addresses, and the adapter-level root cause — are the details to watch for in any follow-up disclosure, as they would establish the full scope and mechanics of the incident.

A comparable incident involving a looping module connected to Safe wallets previously resulted in 114.09 ETH stolen in the Aave v3 Loop Safe Module exploit, illustrating that loop-style adapters interacting with Safe infrastructure have become a recurring attack surface in DeFi.

Why Third-Party Adapter Risk Matters for Multisig Wallets

Safe multisig wallets enforce strong signing thresholds and access controls at the wallet layer, but those guarantees do not extend to every contract a wallet interacts with. When a team adds a third-party adapter, that adapter often receives delegated execution rights or collateral access that sits alongside — not beneath — the multisig's approval layer. In practice, an adapter holding delegated rights can act on wallet funds without going through the multisig's signing workflow, and a flaw in the adapter can therefore circumvent the operational security that the multisig itself provides.

The FlashLoopAdapter incident, as reported by SlowMist, is a direct example of this exposure: the two wallets were reportedly affected not because their signing setup was compromised, but because a connected component introduced a drainable vulnerability.

Operational Security Considerations

Teams operating Safe wallets should treat every module and adapter as an independent security perimeter, reviewing permissions, access scopes, and audit status before connecting them to production wallets. Reviewing which contracts hold delegated access to a wallet, and revoking permissions for adapters that are no longer in active use, is a baseline step that reduces the blast radius if a third-party component is later found to be flawed.

This is not a confirmed remediation for the specific FlashLoopAdapter incident; it reflects standard DeFi operational security practice for any multisig-connected integration. Additional source references were included with the original report.