MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / DeFi / FlashLoop, GoldPesa, MALT: A Week of Smaller DeFi Exploits
DeFi

FlashLoop, GoldPesa, MALT: A Week of Smaller DeFi Exploits

By MABOnChain Desk · Published · Updated · 3 min read

Abstract illustration for FlashLoop, GoldPesa, MALT: A Week of Smaller DeFi Exploits

Published October 5, 2026, 04:36 UTC. Loss figures are estimates from security firms and may change.

Alongside larger incidents this week, three smaller DeFi exploits between October 1 and October 3 cost a combined total of about $490,000, based on security firms' estimates. None broke a major protocol's core contracts. Each targeted custom code built on top of them.

FlashLoopAdapter: about $305,000

An access-control flaw in FlashLoopAdapter, a third-party Safe module used to open and close leveraged Aave V3 positions, was exploited to drain about $305,000 from two Safe multisig wallets, Cointelegraph reported, citing security firm SlowMist. SlowMist put the loss at about 114.09 ETH.

According to SlowMist, a fake Safe contract passed the adapter's authorization check, and the adapter let the caller control the router and transaction data used for swaps. The attacker used that to execute transactions through the victim Safes and drain weETH and other collateral. Around 1,300 WETH of debt was repaid during the attack to unlock the collateral.

"This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3," Aave founder Stani Kulechov said on X, Cointelegraph reported.

GoldPesa GPXHooks: about $114,000

On Base, GoldPesa's Uniswap v4 hook contract, GPXHooks, was allegedly exploited for about $114,000 on October 2, according to Defimon Alerts as reported by The Crypto Times. Defimon described a logic error in the hook's hourly liquidity rebalance.

Defimon said the attacker borrowed 175,000 USDC from Morpho and opened a WETH/USDC position while leaving about 115,000 USDC unpaid. When the attacker triggered the rebalance, the hook burned its own position for about 148,900 USDC, but because balances are netted within the same transaction, it received only about 33,900 USDC. In Defimon's words, the hook effectively paid for the attacker's position. The funds were then converted to USDT and bridged to Solana and BNB Chain, Defimon said. The Crypto Times said it had asked GoldPesa for comment.

MALT: about $72,000

On October 3, SlowMist reported that an attacker drained about $72,000 from MALT through a flaw in its swap function, Coin Edition reported. SlowMist said the function recorded the trader's input before calling a rebalancing hook that pulled DAI from MALT's treasury into the pool. The swap then counted that treasury DAI as if the trader had paid it.

The common thread

All three incidents involved extensions rather than base protocols: a wallet module, a pool hook and a rebalancing step. Users who connect their funds to add-on modules or vaults take on the risk of that extra code, even when the underlying protocol is sound.

The week's largest DeFi incident, a roughly $6 million loss at an unnamed Base vault, is covered in our separate report.

This article is news reporting and is not investment advice.

Sources

Related: NEAR Intents Exploit: Full $3.8M Recovered

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading