Security firm SlowMist says a vulnerability in a third-party adapter called FlashLoopAdapter allowed an attacker to drain collateral from two Safe multisig wallets, underscoring the dependenc
Security firm SlowMist says a vulnerability in a third-party adapter called FlashLoopAdapter allowed an attacker to drain collateral from two Safe multisig wallets, underscoring the dependency risks that extend well beyond the core protocols that DeFi users trust.
What the reported FlashLoopAdapter flaw enabled
According to reporting by CryptoSlate, SlowMist attributed the incident to a flaw in FlashLoopAdapter, a third-party component linked to Aave v3 loop functionality. The firm said the flaw was the entry point that let the attacker move collateral out of two Safe multisig wallets. For related coverage, see South Korea Crypto-Exchange Profits Fall 78% in H1 2026.
The incident, which SlowMist also detailed separately in its alert on the Aave v3 Loop Safe Module exploit involving 114.09 ETH, is notable because Safe multisig wallets are widely regarded as one of the more robust custody setups in Ethereum DeFi. The vulnerability did not originate in Safe itself or in Aave's core contracts; it resided in the adapter sitting between them.
Third-party adapters as an attack surface
The reported flaw highlights a well-documented but often underweighted risk: the composability that makes DeFi powerful also means that the security of a wallet or protocol is only as strong as every external component it integrates. A third-party adapter that manages leveraged loop positions on behalf of multisig wallets carries the authority to move collateral, and a flaw in that adapter can be exploited without touching the underlying protocol.
SlowMist's analysis reinforces a pattern the firm has flagged across multiple ecosystems. Earlier this year the firm's CISO warned of an iOS-level exploit targeting crypto wallet keys, and separately raised compatibility concerns affecting Sui and Aptos, each involving risks that exist at the integration layer rather than within core protocol logic.
Teams and individuals relying on multisig setups for treasury or protocol custody should audit every adapter and module granted permission to interact with their wallets, and monitor SlowMist's public security notices for newly disclosed vulnerabilities. The reported incident involved only two wallets, and SlowMist did not indicate broader exposure in the CryptoSlate report; implying a wider attack surface without supporting evidence would not be accurate.
For Bitcoin holders, the lesson maps cleanly onto the UTXO model's core security argument: self-custody with minimal external dependencies reduces the surface area available to attackers. Every permission granted to a third-party contract or adapter is an assumption that the adapter is correct, audited, and free of logic errors, an assumption this incident shows can fail independently of the protocols it wraps. Separately, a randomness flaw flagged by Coinspect demonstrated similar dependency risk across Bitcoin, Ethereum, and Solana wallets, where the vulnerability resided in a shared library rather than in the chains themselves.
Additional source references: source document 1.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Bitcoininfonews first published the article titled SlowMist Flags FlashLoopAdapter Flaw After Safe Wallet Collateral Drain.