BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

FlashLoopAdapter Flaw Drained Safe Wallet Collateral

Blockchain security firm SlowMist has reported that a vulnerability in a third-party component called FlashLoopAdapter allowed an attacker to drain collateral from two Safe multisig wallets,

AnonymousCryptoCompass newsroom
October 4, 2026
4 min read
NEWS
FlashLoopAdapter Flaw Drained Safe Wallet Collateral
CryptoCompass editorial visual for defi coverage.

Blockchain security firm SlowMist has reported that a vulnerability in a third-party component called FlashLoopAdapter allowed an attacker to drain collateral from two Safe multisig wallets, raising fresh concerns about the risks that external adapters introduce into otherwise hardened custody setups.

What SlowMist Reported About the FlashLoopAdapter Flaw

According to SlowMist, the exploit originated in the FlashLoopAdapter, a third-party module integrated alongside Safe multisig wallets rather than a weakness in the Safe protocol itself. SlowMist attributed the collateral drain directly to a flaw in that adapter, not in Safe's core contracts. The distinction matters because Safe is a widely used multisig framework, and conflating the adapter with the core protocol would misrepresent the scope of the incident. For related coverage, see BlockCon Global Confirms 2026 Speaker Roster: Investors, iGaming Operators and the Web3 infraestructure.

The report follows a pattern SlowMist has documented before. In a prior alert covering the Aave v3 Loop Safe Module exploit involving 114.09 ETH, the firm identified how loop-based flash loan strategies integrated through Safe modules could expose user collateral to attack. The FlashLoopAdapter incident appears to sit within that same category of adapter-level risk. For related coverage, see Traders Fair Uzbekistan 2026: A New Chapter for Central Asia’s Trading Community Begins in Tashkent.

How Two Safe Multisig Wallets Lost Collateral

The attacker targeted two separate Safe multisig wallets, draining collateral from both. Safe multisig wallets, which require multiple private-key signatures to authorize transactions, are a common choice for DeFi users and DAOs seeking stronger security guarantees than a single-key wallet provides. The incident shows that the multisig structure itself does not protect against exploits that operate through an authorized but vulnerable module or adapter. For related coverage, see SEC Approves 3x Leveraged Bitcoin, Ether ETPs for Trading: Bloomberg Analyst.

SlowMist has not disclosed the specific token amounts lost, the transaction hashes, or the identities of the wallet owners in available reporting. Without on-chain confirmation of those details, this article does not assign a dollar figure to the loss. Readers seeking verified on-chain data should monitor SlowMist's official disclosures and cross-reference any transaction claims against Etherscan once full details are published.

Why the Incident Matters for Safe Wallet Users

The core lesson is dependency risk. A Safe wallet's security model is only as strong as the modules and adapters authorized to interact with it. A third-party adapter that has not been rigorously audited can introduce attack surface even when the underlying Safe contracts are sound.

This type of module-level exploit is not theoretical. The Aave v3 Loop Safe Module case SlowMist previously flagged involved 114.09 ETH and demonstrated that looping strategies executed through Safe modules can be manipulated when adapter logic contains flaws. The FlashLoopAdapter incident suggests the pattern has recurred with a different adapter targeting the same architectural weakness.

KEY TAKEAWAYS

  • Third-party adapters carry independent risk. Vetting the Safe protocol is not sufficient if attached modules have not been separately audited.
  • Two wallets were affected. The incident was not isolated to a single user, suggesting the flaw was exploitable across any Safe wallet that had authorized the FlashLoopAdapter.
  • Wait for SlowMist's full disclosure. Specific loss figures and transaction details have not been independently verified at publication. Rely on SlowMist's official post-mortem before drawing conclusions about scope.

Until SlowMist publishes a complete incident report with transaction-level evidence, the full scale of the FlashLoopAdapter exploit remains unconfirmed. Safe wallet users who have authorized any flash loan or loop adapter should review their module permissions and consult SlowMist's advisories for remediation guidance.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Read original article on coinwy.com Read also :