On Oct 1, 2026, a guy got drained for $305k through his own personal helper contract.
He was keeping funds in two Safe multisigs and looping leverage on AAVE: deposit weETH -> borrow WETH -> swap WETH back to weETH -> deposit again -> borrow again. Yield goes up, but so does risk. Doing it manually is a pain, so he wrote himself a software assistant and gave it full access to the wallet — so it could loop everything automatically without needing his signature.
But as always, the "assistant" had holes:
1) It doesn't verify who's calling it. In the open() function, the contract asks msg.sender: "Are you that Safe wallet?" The hacker deployed a contract that simply lies true and gets let in as the owner.
2) Inside, it executed all commands blindly: router.call(data) — where the address and command are set by the attacker. By substituting the victim's Safe and the execTransactionFromModule command (withdraw everything to the attacker), he's in control.
Then it's just a matter of technique:
1) Takes a flash loan of 11,537 WETH (on Morpho, zero fees)
2) Repays the victim's debt of 1,335 WETH on AAVE — the collateral is unlocked
3) Through that exact hole, triggers execTransactionFromModule() and withdraws 1,306 weETH (Safe #1) + 6.4 weETH (Safe #2) to himself
4) Swapping weETH:WETH at 1:1.104, he repays the flash loan and pockets his cut of 114 WETH
~$10 in gas. Adaptability. Persistence. Result. $ETH
