The attack used access-control flaws in FlashLoopAdapter to take funds from two Safe multisignature addresses.