On Oct 1, 2026, a guy got drained for $305k through his own personal helper contract.

He was keeping funds in two Safe multisigs and looping leverage on AAVE: deposit weETH -> borrow WETH -> swap WETH back to weETH -> deposit again -> borrow again. Yield goes up, but so does risk. Doing it manually is a pain, so he wrote himself a software assistant and gave it full access to the wallet — so it could loop everything automatically without needing his signature.

But as always, the "assistant" had holes:

1) It doesn't verify who's calling it. In the open() function, the contract asks msg.sender: "Are you that Safe wallet?" The hacker deployed a contract that simply lies true and gets let in as the owner.

2) Inside, it executed all commands blindly: router.call(data) — where the address and command are set by the attacker. By substituting the victim's Safe and the execTransactionFromModule command (withdraw everything to the attacker), he's in control.

Then it's just a matter of technique:

1) Takes a flash loan of 11,537 WETH (on Morpho, zero fees)

2) Repays the victim's debt of 1,335 WETH on AAVE — the collateral is unlocked

3) Through that exact hole, triggers execTransactionFromModule() and withdraws 1,306 weETH (Safe #1) + 6.4 weETH (Safe #2) to himself

4) Swapping weETH:WETH at 1:1.104, he repays the flash loan and pockets his cut of 114 WETH

~$10 in gas. Adaptability. Persistence. Result. $ETH

ETH
ETHUSDT
2,666.5
-1.13%