BTC $84,802.00 +0.30%
ETH $2,691.97 +0.67%
SOL $120.62 +1.27%
XRP $1.49 +0.44%
Coinwy
News

FlashLoopAdapter Flaw Drained Safe Wallet Collateral

FlashLoopAdapter Flaw Drained Safe Wallet Collateral Thumbnail
Stake.com crypto casino and sportsbook promotion

Blockchain security firm SlowMist has reported that a vulnerability in a third-party component called FlashLoopAdapter allowed an attacker to drain collateral from two Safe multisig wallets, raising fresh concerns about the risks that external adapters introduce into otherwise hardened custody setups.

What SlowMist Reported About the FlashLoopAdapter Flaw

According to SlowMist, the exploit originated in the FlashLoopAdapter, a third-party module integrated alongside Safe multisig wallets rather than a weakness in the Safe protocol itself. SlowMist attributed the collateral drain directly to a flaw in that adapter, not in Safe’s core contracts. The distinction matters because Safe is a widely used multisig framework, and conflating the adapter with the core protocol would misrepresent the scope of the incident. For related coverage, see BlockCon Global Confirms 2026 Speaker Roster: Investors, iGaming Operators and the Web3 infraestructure.

The report follows a pattern SlowMist has documented before. In a prior alert covering the Aave v3 Loop Safe Module exploit involving 114.09 ETH, the firm identified how loop-based flash loan strategies integrated through Safe modules could expose user collateral to attack. The FlashLoopAdapter incident appears to sit within that same category of adapter-level risk. For related coverage, see Traders Fair Uzbekistan 2026: A New Chapter for Central Asia’s Trading Community Begins in Tashkent.

How Two Safe Multisig Wallets Lost Collateral

The attacker targeted two separate Safe multisig wallets, draining collateral from both. Safe multisig wallets, which require multiple private-key signatures to authorize transactions, are a common choice for DeFi users and DAOs seeking stronger security guarantees than a single-key wallet provides. The incident shows that the multisig structure itself does not protect against exploits that operate through an authorized but vulnerable module or adapter. For related coverage, see SEC Approves 3x Leveraged Bitcoin, Ether ETPs for Trading: Bloomberg Analyst.

SlowMist has not disclosed the specific token amounts lost, the transaction hashes, or the identities of the wallet owners in available reporting. Without on-chain confirmation of those details, this article does not assign a dollar figure to the loss. Readers seeking verified on-chain data should monitor SlowMist’s official disclosures and cross-reference any transaction claims against Etherscan once full details are published.

Why the Incident Matters for Safe Wallet Users

The core lesson is dependency risk. A Safe wallet’s security model is only as strong as the modules and adapters authorized to interact with it. A third-party adapter that has not been rigorously audited can introduce attack surface even when the underlying Safe contracts are sound.

This type of module-level exploit is not theoretical. The Aave v3 Loop Safe Module case SlowMist previously flagged involved 114.09 ETH and demonstrated that looping strategies executed through Safe modules can be manipulated when adapter logic contains flaws. The FlashLoopAdapter incident suggests the pattern has recurred with a different adapter targeting the same architectural weakness.

Until SlowMist publishes a complete incident report with transaction-level evidence, the full scale of the FlashLoopAdapter exploit remains unconfirmed. Safe wallet users who have authorized any flash loan or loop adapter should review their module permissions and consult SlowMist’s advisories for remediation guidance.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Read Next

From the Archive