Blockchain security firm SlowMist reported a flaw in FlashLoopAdapter, a third-party integration tool, that allowed an attacker to drain collateral from two Safe multisig wallets, with report
Blockchain security firm SlowMist reported a flaw in FlashLoopAdapter, a third-party integration tool, that allowed an attacker to drain collateral from two Safe multisig wallets, with reporting placing the total taken at 114 ETH.
What SlowMist Identified in the FlashLoopAdapter Flaw
SlowMist attributed the exploit to a vulnerability within FlashLoopAdapter, described by the firm as a third-party component rather than a flaw in Safe's core multisig infrastructure. The adapter reportedly interacted with Aave-related collateral positions, creating an attack surface absent from Safe's native contracts, per CryptoSlate's reporting on the 114 ETH incident. For related coverage, see BlockCon Global Confirms 2026 Speaker Roster: Investors, iGaming Operators and the Web3 Infrastructure.
The distinction matters for scoping the incident: SlowMist's report points to an integration-layer weakness, not a compromise of the Safe multisig protocol itself. Two specific Safe multisig wallets were named as affected, with collateral drained through the adapter's vulnerability. For related coverage, see Traders Fair Uzbekistan 2026: A New Chapter for Central Asia’s Trading Community Begins in Tashkent.
Two Safe Wallets Named as Targets
SlowMist's analysis identified two Safe multisig wallets as the direct victims of the collateral drain. The reported mechanism involved FlashLoopAdapter operating in conjunction with the affected wallets' Aave collateral positions, giving the attacker an unauthorized withdrawal path. For related coverage, see Fintech Revolution Summit –Thailand 2026.
No broader Safe wallet user base was identified as at risk in the reported findings; the incident is bounded to wallets that had integrated with this specific third-party adapter. This targeted vector, where attackers exploit peripheral tooling rather than core protocols, mirrors the pattern documented when fake cold wallet scams drained $6.9M in crypto by exploiting user-facing tooling rather than protocol logic.
Third-Party Adapter Risk in Multisig Deployments
The reported flaw underscores a known attack surface in DeFi: the integration gap between audited core contracts and less-scrutinized third-party adapters. Safe multisig wallets are a security baseline for institutional and DAO treasuries, but their guarantees do not automatically extend to peripheral integrations.
FlashLoopAdapter's role as the entry point illustrates how collateral management tools interacting with lending protocols such as Aave can introduce unauthorized withdrawal paths when access controls are improperly scoped. SlowMist has previously outlined integration-layer risks including agent-poisoning attack surfaces, reinforcing that adapter-level threats compound protocol-level security assumptions.
For multisig operators, the incident reinforces that third-party adapter contracts require the same audit scrutiny applied to primary protocol contracts. A single permissioned call from an unvetted adapter touching collateral positions can bypass the multisig approval threshold if the adapter holds delegated authority over those positions, as the reported exploit demonstrates.
Additional source references: source document 1.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Read original article on marketbit.net