October 05, 2026

On 1 October 2026, a third-party FlashLoopAdapter enabled execution from two Safe accounts. The exploit transaction delivered 114.096151469674448809 ETH to the initiating EOA. The evidence points to delegated module authority, not an exploit of Aave V3 core. SlowMist primary analysis and clarification.
The strongest downstream finding is an exact fee split: 114.030726169100264326 ETH was wrapped, 113.745649353677513666 WETH entered the RAILGUN privacy-system proxy, and 0.285076815422750660 WETH went to the protocol treasury. The visible route ends at that privacy boundary; it does not identify a hidden recipient or prove an exchange cash-out.
Measure / scope | Verified result |
|---|---|
Exploit proceeds received | 114.096151469674448809 ETH; counted once |
Private-pool transfer | 113.745649353677513666 WETH |
Treasury fee | 0.285076815422750660 WETH |
Scope | Ethereum; focused funding and outbound route |
Investigation cutoff | 4 October 2026; block 26122303 |
Evidence basis | SentinelTX call traces and receipts, independently checked Etherscan anchors, SlowMist primary analysis |
The question is not whether a wallet signed the initiating transaction—it did—but whether the victims’ owners signed the Safe executions that removed assets. The traced exploit used module executions. No owner-signed Safe execution was observed in the inspected call tree.
Observed call relationship | Evidence / interpretation |
|---|---|
Adapter → victim Safe 1 | Module execution targeting weETH transfer |
Adapter → victim Safe 2 | Module execution targeting lending-pool withdrawal |
Adapter → execution helper | Additional module execution frames naming the helper as the Safe |
Coverage boundary | 259 frames reported; 134 returned by the trace tool—not a complete replay |
SlowMist reports that open()/close() checked ISafe(msg.sender).isModuleEnabled(address(this)), allowing a fake caller to answer its own authentication check. It then describes attacker-controlled router.call data targeting genuine victim Safes through execTransactionFromModule. This source-level explanation is attributed research; our call-trace evidence supports the module-execution route, but we did not independently compile or replay the adapter. SlowMist primary analysis and clarification. 0x75328f916b1a0878724d364da5eb12b255160b894cb36c63ed5d718efc616fc4.

The implication is a separate authorization boundary: enabling a module grants executable authority beyond the ordinary owner-signature path. SlowMist explicitly clarified that Aave V3 core was unaffected. The current enabled-module lists and the complete set of exposed Safes were not enumerated; two observed victims are not a total exposure count.
The exploit receipt and internal movements show WETH unwrapped into the execution helper and then paid to the attack EOA. Those two legs describe the same 114.096151469674448809 ETH and must be counted once. 0x75328f916b1a0878724d364da5eb12b255160b894cb36c63ed5d718efc616fc4.
Quantity | Classification | Evidence boundary |
|---|---|---|
114.096151469674448809 ETH | Exploit proceeds received | Exact internal transfer |
11,537.2397 WETH | Morpho loan and matching return | Rounded Etherscan display; not stolen-funds total |
1,335.2558 WETH | Debt repayment | Rounded display; victim allocation unresolved |
1,449.3520 WETH | Swap output | Rounded display; not an additional loss |
The large flash loan provides temporary liquidity for repayment and collateral release. It was returned, so counting it as stolen funds would inflate the incident by two orders of magnitude. Proceeds received are also not necessarily each victim’s gross collateral loss: debt repayment changes the net economic calculation. Exact ERC20 amounts per victim remain unresolved, so this report does not assign a definitive loss to each Safe.
Subtracting only exploit-transaction gas gives 114.092231045147641069 ETH. That is an arithmetic subtotal, not an all-in profit claim: deployment costs, forwarding costs and other activity are not completely reconciled.
The forwarding transfer is larger than the exploit receipt because the EOA had pre-existing funding. It cannot be treated as an exclusively stolen-funds figure. The next transaction converts the gross ETH input to WETH and divides it between the privacy-system proxy and treasury. 0x3a5663d9a3d32bdea3c3012fd9dbaf490195ed413204c4db8f1097e1e7f753f9. 0xa20636bf3792f705ae51a48afdec336fb0518cd43365a8fc3e596dea23266dc9.

Shield receipt leg | Exact WETH | Log |
|---|---|---|
Wrapped input | 114.030726169100264326 | 262 |
Transfer to privacy-system proxy | 113.745649353677513666 | 266 |
Transfer to treasury | 0.285076815422750660 | 267 |
Shield event | Supports the amount / fee split | 268 |

The two transfers sum exactly to the wrapped input. The treasury fee is 0.25% rounded down at token precision; transaction gas of 0.001793902352363730 ETH is separate. The treasury leg is a protocol fee—not evidence of cash-out, common ownership, or a recovery target. We independently checked these visible Etherscan logs against the SentinelTX follow-up result.
All times below are UTC on 1 October 2026. These are selected transaction anchors, not a claim that every intervening transaction has been accounted for.
UTC / block | Event | Amount |
|---|---|---|
14:15:23 / 26098000 | RAILGUN withdrawal funds attack EOA | 0.049875 ETH net received |
15:08:47 / 26098264 | Exploit helper pays attack EOA | 114.096151469674448809 ETH |
16:45:59 / 26098748 | Attack EOA forwards to intermediate EOA | 114.130726169100264326 ETH |
16:46:59 / 26098753 | Intermediate EOA sends Relay Adapt input | 114.030726169100264326 ETH |
A same-transaction call chain directly connects the initiating EOA, helper, adapter and victim executions. Two later transaction hashes directly connect the initiating EOA to the forwarding EOA and Relay Adapt. These are transaction relationships, not human attribution.
Proposed connection | Evidence level | Conclusion |
|---|---|---|
Attack EOA → helper → adapter → victims | Direct inspected call trace | Execution relationship established |
Attack EOA → forwarding EOA → RAILGUN | Direct value transfers | Visible disposition route established |
Funding withdrawal and shield use same public service | Shared service pattern | Does not establish hidden owner continuity |
Similar-looking addresses | Potential poisoning | Do not merge into attacker cluster |
Post-shield withdrawal of similar size | Heuristic only | Amount / timing alone cannot attribute funds |
The traced scope is Ethereum. Two reported Optimism activities were not inspected. Adapter source code, the complete incident-block module lists, helper deployment provenance and exact exploit ERC20 allocation were not independently established. Historical owner/setup claims from the first automated result were withdrawn in the follow-up and are not used here.
The RAILGUN funding-transaction signer may be an independent relayer. Shared public infrastructure does not identify an operator. No exchange endpoint was identified in the inspected routes; that is narrower than proving no exchange cash-out occurred. The private-pool transfer cannot be followed to a particular hidden withdrawal using these public records alone.
Visible noncustodial EOA balances are not automatically freezeable. We also do not describe the helper’s deployment as the only remaining lead: unexamined histories, module exposure and alternate infrastructure remain separate questions.
Question | Practical investigation action |
|---|---|
Which Safes retain this authority? | Enumerate adapter-enabled Safes and incident-block module lists; validate current exposure before remediation |
How much did each victim lose net of debt? | Reconcile full exploit receipt transfers, collateral withdrawal and debt repayment per account |
Was infrastructure reused? | Identify helper deployer and inspect funding counterparties; avoid shared-service ownership assumptions |
Can downstream funds be attributed? | Treat pool exit matches as leads; require independent evidence before attribution or exchange requests |
For affected account operators, the relevant control is the specific module’s execution authority. A verified vulnerable-module exposure warrants targeted module revocation and preservation of account state and receipts. This is distinct from a blanket assertion that Safe or Aave core is compromised.
Role | Full address |
|---|---|
Attack EOA | |
Execution helper | |
Third-party adapter | |
Victim Safe 1 | |
Victim Safe 2 | |
Forwarding EOA | |
RAILGUN Relay Adapt | |
RAILGUN privacy-system proxy | |
RAILGUN Treasury |
Role | Full transaction hash |
|---|---|
Funding withdrawal | 0xc5dc2606e42ebfad29fce601056248b9b3f3571318c9a0de2910ac7c0363852b |
Exploit | 0x75328f916b1a0878724d364da5eb12b255160b894cb36c63ed5d718efc616fc4 |
Forwarding | 0x3a5663d9a3d32bdea3c3012fd9dbaf490195ed413204c4db8f1097e1e7f753f9 |
Shield / fee split | 0xa20636bf3792f705ae51a48afdec336fb0518cd43365a8fc3e596dea23266dc9 |
Primary mechanism and scope clarification: SlowMist primary analysis and clarification. Incident index: SlowMist Hacked. Transaction references above are Etherscan records. SentinelTX was used for call-trace and receipt analysis; the shield accounting and exploit anchor were cross-checked against visible explorer records. The report separates directly observed transfers, attributed source-code findings and analytical inference.
The central result is a module-authority route yielding a precisely observed ETH receipt, followed by a fee-reconciled privacy-pool entry. A large flash loan is not the loss figure, a protocol fee is not cash-out, and a privacy endpoint is not an identified attacker.
6 reads