File #002 · FlashLoopAdapter exploit (Aave-linked)MONITORINGv0.1 · findings locked · Oct 2, 2026

Railgun in. Railgun out.

Railgun→Attacker wallet→FlashLoopAdapter · 2 Safes→Fresh address→Railgun

The 114.1 ETH taken from two Safe wallets was back in a privacy pool 98 minutes after the exploit. The attacker's wallet was funded from Railgun 53 minutes before the attack and emptied into Railgun at 16:46 UTC. Aave's pools were used, not broken. We rebuilt the exploit transaction and the wallets around it from raw chain data. Every figure below is tied to a transaction.

114.10ETHKept by the attacker, out of one transaction. Reported as ≈ $305k.
98minFrom the exploit (15:08 UTC) to the funds entering Railgun (16:46 UTC).
11,537WETHFlash-borrowed from Morpho and repaid in the same transaction.
10%Bounty offered on-chain by the Safes' owner. Deadline Oct 3, 18:00 UTC.
MONITORING

In Railgun

114.03 ETH

Last visible move

Oct 1, 16:46 UTC

Bounty deadline

Oct 3, 18:00 UTC

Last checked

Oct 2, 10:40 UTC

The findings are locked. The status bar updates when the watched addresses move. Additions are logged below.

The claim

"Aave Hack: FlashLoopAdapter Hits Two Safe Wallets"

Cryptonews headline, Oct 2 Attributed

"This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3."

Stani Kulechov, Aave, as reported Project-reported

The evidence

  • Verified

    Aave's pool did what it is built to do: it accepted a debt repayment and released collateral. Nothing in the transaction breaks an Aave contract.

  • Verified

    Both Safes log ExecutionFromModuleSuccess: their enabled module, FlashLoopAdapter, moved the funds.

  • Verified

    114.096 ETH went to the attacker. 114.03 ETH was shielded into Railgun 98 minutes later.

  • Verified

    Both Safes have one owner, 0x329c…3eD4, threshold 1. Blockscout labels that address "AAVE: Deployer 13" Label attributed.

The unknown

  • Unknown

    Where the ETH goes after Railgun.

  • Unknown

    Who the attacker is.

  • Unknown

    Whether the bounty will be accepted.

  • Attributed

    The exact flaw. SlowMist describes it as an access-control bug in the adapter.

01 · The window

Two and a half hours in the open.

The attacker's wallet existed in public for 2 hours 31 minutes, from Railgun funding to Railgun deposit. The exploit itself was one transaction. The Safes' owner wrote to an already empty wallet 4 hours 17 minutes after the funds were gone.

2026-10-01 · UTC

Hover a marker for the transaction

Chart loading…

Shaded: the time the funds were outside a privacy pool. Red rings are look-alike addresses sending fake "ETH" to the attacker after the funds had moved.

02 · Key findings

What the chain shows.

F1

The trail starts and ends in Railgun

Verified

At 14:15 UTC the attacker's wallet 0x42c2…9353 received 0.049875 ETH through Railgun's RelayAdapt: 0.05 WETH unshielded, minus Railgun's 0.25% fee. At 16:45 it sent its whole balance, 114.13 ETH, to a fresh address 0x951A…2f1a. One minute later that address shielded 114.03 ETH back into Railgun. The Railgun contract logged a Shield event and took its 0.25% fee (0.285 WETH). After that point the funds cannot be followed on-chain.

Evidence: 0xc5dc2606…852b (funding), 0x3a5663d9…53f9 (empty), 0xa20636bf…6dc9 (shield).

F2

Aave's pools were used, not broken

Verified

Inside the exploit transaction, Aave received a 1,335.26 WETH repayment of Safe 1's debt and released 1,306.48 weETH of Safe 1's collateral. That is normal pool behaviour. What failed was the decision to do it: the Safes' module, FlashLoopAdapter, carried it out for a caller that was not the owner.

Evidence: 0x75328f91…6fc4, logs 1017–1027.

F3

One transaction, five protocols

Verified

Morpho lent 11,537 WETH for the length of the transaction. The attack contract repaid Safe 1's Aave debt, took its weETH and 6.43 weETH from Safe 2, sold 1,312.9 weETH through ParaSwap (routed via Curve, Fluid and Uniswap v3 and v4) for 1,449.35 WETH, repaid Morpho and unwrapped the difference: 114.096 ETH.

Evidence: 0x75328f91…6fc4, block 26,098,264.

F4

The attacker prepared for 53 minutes

Verified

After the Railgun funding at 14:15 UTC, the wallet deployed a helper contract at 14:44, sent itself an empty transaction at 14:56, and had the helper create the attack contract 0xF091…67ff at 15:02. The exploit followed six minutes later. The attack contract's code is not verified.

Evidence: 0x378c128d…8e71, 0x0c2bbaf2…3884.

F5

The owner of both Safes offered a 10% bounty on-chain

Verified messageLabel attributed

At 21:03 UTC, 0x329c…3eD4, the only owner of both Safes, sent the attacker a message: keep 11.41 ETH, return 102.69 ETH before Oct 3, 18:00 UTC, and the matter is treated as a whitehat rescue. The wallet it reached had been empty since 16:45. Blockscout labels the sender "AAVE: Deployer 13". We read the ownership from the Safes themselves; the label is Blockscout's.

Evidence: 0x94b69189…89d0 (message in the input data).

F6

Address poisoners targeted the attacker

Verified

From 17:00 UTC, addresses starting 0x951A and ending 2f1a, imitating the attacker's fresh address, sent fake "ETH" tokens and dust to the attacker's wallet. It is the same trick seen in File #001, this time aimed at a thief. We filtered these before counting any flow.

Evidence: e.g. 0x951A25c9…0f1a, 0x951b4647…2f1a.

03 · Money flow

Where the 1,449 WETH came from, and where it went.

The Safes' weETH was sold for 1,449.35 WETH. Most of it paid off Safe 1's own Aave debt. The rest, 114.10 ETH, went to the attacker. Morpho's 11,537 WETH flash loan went in and out of the same transaction and is not shown.

Value by route, WETH

Hover a band for amounts

Chart loading…

The Safes' shares of the sale are split in proportion to the weETH taken from each (1,306.48 and 6.43 weETH, sold at 1.1039 WETH per weETH). On that basis Safe 1 lost ≈ 107 ETH of net value and Safe 2 ≈ 7 ETH.

04 · The whole trail

Every edge shows its evidence. Click one.

A grey line is a transfer we read on-chain. A dotted box is a name taken from a public label or a verified contract name. Railgun is where the trail ends.

BEFORE · 14:15 EXPLOIT TX · 15:08 INSIDE THE TX AFTER · 16:45 MESSAGE 114.10 ETH 114.13 ETH 114.03 ETH Railgun0.05 WETH unshielded Attacker wallet0x42c2…9353 Attack contract0xF091…67ff · unverified Safe 11,306.48 weETH Safe 26.43 weETH ParaSwap sale→ 1,449.35 WETH AaveSafe 1 debt repaid Attacker wallet0x42c2…9353 Fresh address0x951A…2f1a Railguntrail ends · 16:46 Bounty message21:03 · from Safe owner

Click or tap any line in the map to see its evidence: status, transactions, time and amount.

Verified transferDirect cross-chain linkInferred linkNamed by label

05 · Evidence map

Every link, and what supports it.

LinkEvidenceStatus
Railgun → attacker walletRelayAdapt unwraps 0.05 WETH unshielded from Railgun's contract (0.25% fee) and pays 0.049875 ETHVerified
Attacker → attack contractContract creations at 14:44 and 15:02; the exploit is sent from the same walletVerified
Morpho flash loan11,537.24 WETH out and back in the exploit transactionVerified
FlashLoopAdapter acted on both SafesExecutionFromModuleSuccess logged by each SafeVerified
Why the module obeyed the attackerSlowMist: access-control flaw in the adapterAttributed
Safe 1 debt repaid, collateral released1,335.26 WETH into Aave's WETH pool; 1,306.48 aEthweETH burnedVerified
weETH → WETH via ParaSwap1,312.9 weETH in, 1,449.35 WETH back, through AugustusV6Verified
Exploit → attacker wallet114.096 ETH internal transfer from the attack contractVerified
Attacker → fresh address → Railgun114.13 ETH at 16:45; 114.03 ETH shielded at 16:46 with a Railgun Shield eventVerified
After RailgunShielded balances are private by designUnknown
Safes' ownergetOwners() on both Safes returns 0x329c…3eD4, threshold 1Verified
"AAVE: Deployer 13"Blockscout's label for 0x329c…3eD4Attributed
Bounty offerText in the input data of 0x94b69189…89d0Verified message
Verified
  • 114.096 ETH to the attacker in one transaction
  • Railgun funding at 14:15 and Railgun deposit at 16:46
  • Aave debt repaid and collateral released, as designed
  • Both Safes owned by 0x329c…3eD4
  • 10% bounty offer, deadline Oct 3 18:00 UTC
Attributed
  • Access-control flaw (SlowMist)
  • "AAVE: Deployer 13" label (Blockscout)
  • ≈ $305k loss (press)
  • First alert: Defimon
Project-reported
  • Aave: a third-party adapter, no effect on Aave v3
Unknown
  • Movements after Railgun
  • Who the attacker is
  • Who built and runs the adapter
  • Whether the bounty is accepted

Headlines called this an "Aave hack". On-chain, Aave's contracts behaved as designed; the module the Safes had enabled is what moved the funds. The Safes' owner carries an "AAVE: Deployer 13" label on Blockscout, so the victims may be Aave-linked wallets. We report the label, not a conclusion.

06 · Timeline

In order.

Oct 1 · 14:15Attacker wallet funded from Railgun: 0.049875 ETH
Oct 1 · 14:44Wallet deploys a helper contract 0x4a41…f84a
Oct 1 · 15:02Helper creates the attack contract 0xF091…67ff
Oct 1 · 15:08Exploit: two Safes drained through FlashLoopAdapter, 114.096 ETH to the attacker
Oct 1 · ≈15:09Defimon alert, then SlowMist analysis Attributed
Oct 1 · 16:45Wallet emptied to a fresh address: 114.13 ETH
Oct 1 · 16:46Fresh address shields 114.03 ETH into Railgun
Oct 1 · 17:00Look-alike addresses start poisoning the attacker's wallet
Oct 1 · 21:03Safes' owner offers a 10% bounty on-chain
Oct 3 · 18:00Bounty deadline

07 · Ledger

The transactions.

All 12 ground-truth rows. Steps inside the exploit share one transaction hash.

Transactions
UTCEventAmountTransaction
Oct 1 · 14:15:23Attacker wallet funded through Railgun RelayAdapt0.049875 ETH0xc5dc2606…852b
Oct 1 · 14:44:23Wallet deploys helper contract 0x4a41…f84a—0x378c128d…8e71
Oct 1 · 15:02:47Helper creates attack contract 0xF091…67ff—0x0c2bbaf2…3884
Oct 1 · 15:08:47Flash loan from Morpho Blue (repaid in the same transaction)11,537.24 WETH0x75328f91…6fc4
Oct 1 · 15:08:47Safe 1 Aave WETH debt repaid1,335.26 WETH0x75328f91…6fc4
Oct 1 · 15:08:47Safe 1 weETH collateral withdrawn1,306.48 weETH0x75328f91…6fc4
Oct 1 · 15:08:47Safe 2 weETH taken6.43 weETH0x75328f91…6fc4
Oct 1 · 15:08:47weETH sold through ParaSwap AugustusV61,312.90 weETH0x75328f91…6fc4
Oct 1 · 15:08:47Profit unwrapped and sent to the attacker wallet114.096 ETH0x75328f91…6fc4
Oct 1 · 16:45:59Attacker wallet emptied to fresh address 0x951A…2f1a114.131 ETH0x3a5663d9…53f9
Oct 1 · 16:46:59Fresh address shields into Railgun114.031 ETH0xa20636bf…6dc9
Oct 1 · 21:03:23Bounty message from the Safes’ owner 0x329c…3eD40 ETH0x94b69189…89d0

08 · Method and standard

How we know.

We read the exploit transaction's token transfers, internal transfers and event logs, then each wallet's full history, from Blockscout's public Ethereum API. Safe ownership comes from calling getOwners() and getThreshold() on each Safe. Our engine then traced the case from the attacker's wallet on its own and recovered every transfer it was expected to find. ETH prices are not needed for the findings; dollar figures are the press's.

Verified

Read on-chain by us. A direct link is proven by records on both chains.

Inferred

Our deduction from patterns. The method is stated.

Attributed

Someone else's claim or label. The source is named.

Project-reported

A statement from the project involved.

Unknown

What we could not establish, listed.

Sources