SlowMist Attributes Safe Wallet Collateral Drain to FlashLoopAdapter Flaw, Not Core Multisig Contracts
Key Takeaways
- •SlowMist attributed the collateral drain from two Safe multisig wallets to a vulnerability in the third-party FlashLoopAdapter component rather than Safe's core multisig contracts.
- •The exact amount lost, the identity of the attacker, and the precise incident timeline have not been confirmed in available sources.
- •Third-party adapters inherit permission to interact with wallet-held assets, expanding the attack surface beyond Safe's own audited contracts.
- •The reported flaw applies specifically to FlashLoopAdapter, and current evidence does not indicate that all Safe wallet deployments or adapter integrations are compromised.
- •Teams operating flash-loan loop adapters with collateral-holding Safe wallets are advised to audit integration permissions, revoke unnecessary approvals, and monitor official security advisories.

Blockchain security firm SlowMist has attributed the drain of collateral from two Safe multisig wallets to a vulnerability in a third-party component known as FlashLoopAdapter, stating that the flaw sits outside Safe's core wallet infrastructure. The finding shifts attention from the widely used multisig contracts themselves to the peripheral tooling connected to them.
What SlowMist Reported About the FlashLoopAdapter Flaw
According to SlowMist, the vulnerability was not located in Safe's core multisig contract but in a third-party adapter called FlashLoopAdapter, and the firm directly attributed the collateral loss to that component, placing the root cause outside the primary wallet infrastructure. Two Safe multisig wallets were identified as affected, with collateral drained as a result of the reported flaw.
SlowMist has not, in the information available, confirmed the exact dollar or token amount lost, the identity of the attacker, or the precise timeline of the incident. In a comparable case, CryptoSlate reported that hackers exploited a third-party Aave-related tool to steal 114 ETH, illustrating a recurring pattern of peripheral adapter exploits targeting DeFi-adjacent infrastructure.
What the Report Does and Does Not Confirm
SlowMist's attribution centers on FlashLoopAdapter as the flawed component. The report, as available, does not characterize the incident as a failure of Safe's multisig signing logic or its guardian module architecture. Claims about the specific exploit path, the affected deployment versions, or the patching status remain unconfirmed pending official remediation guidance from the relevant project teams.
Why Third-Party Adapter Risk Matters for Safe Multisig Wallets
Safe multisig wallets are widely used across DeFi protocols to custody collateral, manage treasury assets, and execute governance transactions. Multisig designs require multiple authorized keys to approve each transaction, so that no single compromised key can move funds on its own. When teams integrate third-party adapters, those components inherit permission to interact with wallet-held assets, expanding the attack surface beyond what Safe's own audited contracts cover.
The FlashLoopAdapter case, as described by SlowMist, demonstrates that a flaw in a peripheral integration can be sufficient to drain collateral even when the underlying multisig logic is sound. Security researchers have flagged this pattern repeatedly: in a composable DeFi stack, the weakest link is rarely the core protocol. Teams handling high-value wallets that have integrated similar adapter tooling should treat the report as a prompt for an immediate permissions review, a consideration equally relevant to any protocol monitoring its exposure to third-party tooling with elevated access to wallet assets.
Scope Limitations
The reported flaw affects FlashLoopAdapter specifically. There is no basis in the current evidence to characterize all Safe wallet deployments, or all adapter integrations, as compromised. Teams not using FlashLoopAdapter should still audit their own third-party integration permissions as a general practice.
What Wallet and Protocol Teams Can Review After the Report
The report establishes that SlowMist attributes the collateral drain to a flaw in FlashLoopAdapter, a third-party component, rather than Safe's core multisig contracts, and that two Safe multisig wallets were reportedly affected, while the loss amounts and a confirmed exploit path have not been verified in available sources. Teams using third-party adapters with collateral-holding Safe wallets should audit integration permissions and monitor official project channels for remediation guidance.
Immediate Review Priorities
Any team running a Safe multisig that has integrated FlashLoopAdapter, or similar flash-loan loop adapters — tooling generally used to automate repeated collateral-and-borrow loops on lending protocols — should audit which permissions those contracts hold over wallet assets, revoke unnecessary approvals, and cross-reference contract addresses against SlowMist's published findings once a full disclosure is available. For verified remediation steps, teams should follow SlowMist's official channels and the Safe ecosystem's security advisories directly rather than relying on secondary summaries.
The broader lesson extends to creator and protocol treasury management: as DeFi infrastructure becomes more composable, the security posture of a multisig wallet is only as strong as the least-audited integration it permits. Protocol teams managing on-chain treasuries or collateral pools should establish a routine of adapter permission reviews, independent of whether a specific incident has been reported against their stack. Security events in this category, as tracked across the Web3 security research community, consistently point to third-party integrations as the entry point rather than core protocol failures.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.