FlashLoopAdapter Flaw Drains Collateral From Two Safe Wallets
Blockchain security firm SlowMist has identified a flaw in a third-party component called FlashLoopAdapter that reportedly allowed an attacker to drain collateral from two Safe multisig wallets.
Blockchain security firm SlowMist has identified a flaw in a third-party component called FlashLoopAdapter that reportedly allowed an attacker to drain collateral from two Safe multisig wallets. The finding points to a class of integration risk that sits outside the core multisig controls Safe provides, raising questions about how teams vet the adapters and modules they connect to their wallets.
TLDR Keypoints
- SlowMist attributed the incident to a flaw in FlashLoopAdapter, a third-party adapter, not a vulnerability in Safe itself.
- An attacker exploited the flaw to drain collateral from two separate Safe multisig wallets.
- The reported impact was collateral loss; no confirmed loss figures, transaction hashes, or attacker addresses are available from the current disclosure.
What SlowMist Reported About the FlashLoopAdapter Flaw
According to SlowMist, the vulnerability resided in FlashLoopAdapter, described as a third-party adapter rather than a native Safe contract. The flaw gave an attacker a path to extract collateral from two wallets that had integrated the component, while Safe’s multisig signing logic remained intact. This distinction matters because it shifts the attack surface from Safe’s well-audited core to a peripheral integration point. For related coverage, see BlockCon Global Confirms 2026 Speaker Roster: Investors, iGaming Operators and the Web3 infraestructure.
SlowMist attributed collateral drainage as the reported impact. The full technical root cause, including any specific call paths, re-entrancy vectors, or access control failures, has not been confirmed in the current disclosure. All incident claims here are attributed solely to SlowMist’s reported findings. For related coverage, see Traders Fair Uzbekistan 2026: A New Chapter for Central Asia’s Trading Community Begins in Tashkent.
A comparable incident involving a looping module connected to Safe wallets previously resulted in 114.09 ETH stolen in the Aave v3 Loop Safe Module exploit, illustrating that loop-style adapters interacting with Safe infrastructure have become a recurring attack surface in DeFi. For related coverage, see Fintech Revolution Summit –Thailand 2026.
Why Third-Party Adapter Risk Matters for Multisig Wallets
Safe multisig wallets enforce strong signing thresholds and access controls on the wallet layer, but those guarantees do not extend to every contract a wallet interacts with. When a team adds a third-party adapter, that adapter often receives delegated execution rights or collateral access that sits alongside, not beneath, the multisig’s approval layer. A flaw in the adapter can therefore circumvent the operational security that multisig provides. For related coverage, see Cyber Revolution Summit Vietnam 2026.
The FlashLoopAdapter incident, as reported by SlowMist, is a direct example of this exposure: two wallets were reportedly affected not because their signing setup was compromised, but because a connected component introduced a drainable vulnerability. Teams operating Safe wallets should treat every module and adapter as an independent security perimeter, reviewing permissions, access scopes, and audit status before connecting them to production wallets.
Reviewing which contracts hold delegated access to a wallet, and revoking permissions for adapters that are no longer in active use, is a baseline step that reduces the blast radius if a third-party component is later found to be flawed. This is not a confirmed remediation for the specific FlashLoopAdapter incident; it reflects standard DeFi operational security practice for any multisig-connected integration.
Additional source references: source document 1, source document 2.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Defiliban · Oliver Benjamin
Oliver Benjamin
@oliver-benjamin