Blockchain security firm SlowMist has reported that a flaw in a third-party component called FlashLoopAdapter allowed an attacker to drain collateral from two Safe multisig wallets. The affected adapter is a separate integration layer, not a vulnerability in Safe’s own multisig contracts, a distinction SlowMist’s report makes clear.
KEY POINTS
- SlowMist reported the incident, attributing the exploit to a flaw in the third-party FlashLoopAdapter.
- The vulnerable component is a third-party adapter, not Safe’s native multisig software.
- Two Safe multisig wallets reportedly had collateral drained through the compromised integration.
SlowMist Reports FlashLoopAdapter Flaw Behind the Safe Wallet Collateral Drain
According to SlowMist’s report, the FlashLoopAdapter served as a third-party integration that interacted with Safe multisig wallets. The flaw within that adapter gave an attacker a path to access and drain collateral held by two of the affected wallets. SlowMist, which has previously tracked broader patterns of Web3 security risks across the DeFi ecosystem, attributed the incident specifically to the adapter layer. For related coverage, see Trust Wallet Initiates Compensation for $7 Million Hack.
A report by CryptoSlate covering a related exploit involving a third-party Aave tool illustrates how external integrations with major DeFi infrastructure can introduce vulnerabilities that bypass the security controls of the underlying protocol itself.
The Attack Path Through a Third-Party Adapter
Safe multisig wallets require multiple signers to approve transactions, which makes the core custody layer resilient. However, when users or protocols grant permissions to a third-party adapter, that adapter can act on behalf of the wallet within the scope of those permissions. A flaw in the adapter’s logic, access controls, or upgrade path can be exploited without compromising Safe’s own contracts.
In this case, SlowMist’s report points to FlashLoopAdapter as the entry point. The collateral drain affected two wallets that had interacted with the adapter, suggesting the exploit was scoped to users of that specific integration. SlowMist’s monthly Web3 loss reports have consistently shown that third-party integrations and approval-based exploits account for a significant share of DeFi losses.
Why Third-Party Adapters Create Risk Around Multisig Collateral
Delegated Permissions vs. Wallet Custody Controls
A Safe multisig wallet controls who can sign transactions. But when a user approves a third-party contract to manage positions, supply collateral, or execute loops on their behalf, that approval delegates real financial authority outside the multisig’s signing threshold. If the approved contract contains a flaw, attackers can exploit it without needing the wallet’s private keys or owner signatures.
This type of risk is not unique to Safe wallets. As MEV-related exploits on other platforms have shown, approved contract permissions are a persistent attack surface in DeFi, particularly when the approved contract is developed and maintained by a team separate from the underlying protocol.
Reviewing Third-Party Contract Permissions Before Use
Security researchers consistently recommend that users audit what permissions they have granted to external contracts, and that protocol teams review upgrade paths, access controls, and emergency pause mechanisms before deploying adapter-style integrations. An adapter that holds upgrade authority or broad approval to move collateral represents concentrated risk.
SlowMist’s earlier work on address-level attack vectors illustrates how attackers scout wallet behaviors before executing. Third-party adapters with predictable permission structures can become targets in the same way.
What Users and Protocol Teams Should Check After the Report
Verify Whether You Used the FlashLoopAdapter Integration
Users who interacted with FlashLoopAdapter or any protocol that deployed it should check official communications from the affected project for guidance. The relevant check is whether a given Safe wallet granted approvals or delegated control to the FlashLoopAdapter contract. Block explorers such as Etherscan allow users to review active token approvals and contract interactions for any wallet address.
For Protocol Teams: Permission Review and Incident Response
Teams integrating third-party adapters into their products should review delegated contract permissions, assess whether affected wallets require action, and communicate transparently with users. Incident response timelines, official contract addresses to revoke, and remediation steps should come from the teams directly involved; users should wait for verified official guidance before taking any on-chain action.
For Southeast Asian DeFi participants using platforms that may have integrated similar flash-loop-style adapters, the immediate priority is monitoring official channels from relevant projects and using on-chain approval checkers to audit wallet exposure. Regional platforms that support DeFi access should also monitor for any downstream user impact from the reported incident.
Additional source references: source document 1.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
