SlowMist flags FlashLoopAdapter as the weak link
SlowMist identified FlashLoopAdapter as the source of the exploit. The component is a third-party adapter, entirely separate from the Safe multisig wallet protocol. That distinction matters: the core Safe contracts were not compromised. The flaw lived one layer out, in code plugged into Safe from outside. For related coverage, see Is Ravencoin Still Worth Buying with BTC in 2026?.
According to reporting by CryptoSlate, the attacker exploited how FlashLoopAdapter handled collateral during flash loan sequences, ultimately walking away with 114 ETH from two targeted wallets. SlowMist, which has a consistent track record tracing exploits back to peripheral integrations, flagged the incident and attributed the root cause to the adapter’s logic, not Aave or Safe directly. For related coverage, see Traders Fair Uzbekistan 2026: A New Chapter for Central Asia’s Trading Community Begins in Tashkent.
This is not the first time the firm has traced a significant loss to an adjacent vulnerability. SlowMist previously documented a separate case involving the Liquid Network exploit that minted 3,998 L-BTC, where the attack vector similarly bypassed a core protocol’s defenses through a peripheral component. For related coverage, see Fintech Revolution Summit –Thailand 2026.
Reported impact: collateral drained from two Safe wallets
The reported target count is two Safe multisig wallets. What was taken was collateral, not a full wallet balance sweep. That framing from SlowMist is specific: collateral locked in positions accessible through FlashLoopAdapter was what the attacker could reach.
CryptoSlate’s coverage puts the confirmed figure at 114 ETH stolen via the third-party Aave tool. Whether additional wallets had authorized FlashLoopAdapter but escaped the attack is not confirmed in available reporting.
Why third-party integrations expand multisig risk
Safe wallets are widely regarded as among the most secure custody setups in DeFi. But security is only as strong as the weakest integration point. When users authorize third-party adapters to interact with their wallets, those adapters inherit execution privileges. A flaw in the adapter’s logic can be weaponized even when the wallet itself behaves exactly as designed.
The FlashLoopAdapter case fits that pattern precisely: a trusted outer layer with a flaw in something plugged into it. Anyone using Safe wallets alongside automated DeFi strategies, including those built around the broader Web3 infrastructure ecosystem being discussed at major industry events, now has a concrete reminder that adapter authorization is not a low-stakes decision.
SlowMist has not publicly detailed remediation steps based on available information, and it is not confirmed whether the affected wallets have been made whole. The attacker’s identity remains unknown from publicly available reporting.
How many more wallets authorized FlashLoopAdapter before this flaw was caught? That number, if it surfaces, will define the true blast radius of this exploit.
Additional source references: source document 1.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.