CryptoMedium•2 October 2026•
1 min read

Aave v3 Helper Contract Vulnerability Leads to 114.09 ETH Drain

Key Facts

1Approximately 114.09 ETH was drained from two Safe multisig wallets due to an access control bypass in a helper contract for Aave v3.

Attackers drained approximately 114.09 ETH from two Safe multisig wallets due to a security vulnerability in a helper contract associated with the Aave v3 protocol. cryptoticker.io reported that the exploit targeted a specific component known as the FlashLoopAdapter by bypassing access control mechanisms, allowing the funds to be withdrawn on October 1, 2026.

Reports confirmed that the core Aave v3 pools and the Safe core infrastructure were not compromised in this incident, as the damage was limited to users of the specific module. The operation was financed through a flash loan from Morpho involving 11,537 WETH, while no official statements from the Aave or Safe teams were available as of October 2, 2026.