Exploit Drains $7.8M In rsETH From User’s Safe Wallet Through Compromised Strategy Executor

Blockchain security firms Blockaid, PeckShield, and BlockSec have confirmed an exploit that drained approximately $7.8 million worth of rsETH, around 2,900 tokens, from a Gnosis Safe wallet on Ethereum. The incident began at 04:38 UTC with a transaction that moved the bulk of the funds, followed by several smaller transactions over the next hour totaling an additional ~$160,000, according to the firms’ reports.
The root cause was a flawed authorization check in the executor contract, identified by analysts as address 0x4f0055926c839D1d960a82CBF84E2eE933958ebC.
The targeted Safe, belonging to a large holder of leveraged rsETH, relied on a whitelisted strategy executor module that exposed a recipe entrypoint. This entrypoint forwarded fully caller-supplied calldata into the Safe’s execTransactionFromModuleReturnData function using operation=1 (DELEGATECALL) without gating the external caller. Setting the supplied contract parameter to the executor’s own address passed validation, meaning anyone who could reach the entrypoint could execute arbitrary code within the Safe’s own context — effectively gaining full control over its assets.
The attacker used a public keeper multicall to route the authorized Uni V4 LP Safe module into an attacker-created hooked Uniswap V4 pool, executing via Permit2 and the PositionManager. The attacker had deployed a worthless token dubbed the “Permissionless Attacker Token” (PAT) and supplied roughly 2,900 aEthrsETH as liquidity against it. A custom hook in the pool unwrapped the aEthrsETH into rsETH and siphoned it out of the Safe, which was left holding a valueless LP NFT.
MEV Bot Front-Runs Attack; KelpDAO Imposes Temporary Pause
Notably, the original attack transaction never reached its intended beneficiary. The attacker launched the exploit directly into the public mempool, where it was front-run by an MEV bot named “yoink,” which captured the entire ~2,882 rsETH — worth roughly $7.8 million — and routed it to address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. In effect, a maximal extractable value bot, not the attacker, walked away with the stolen funds.
In response, KelpDAO announced it had detected suspicious activity on the receiving address and placed it under a precautionary 24-hour pause, during which rsETH cannot move in or out. The team stated it is working with security experts on the investigation, and emphasized that the measure is wallet-level only: Kelp contracts remain safe, rsETH stays fully backed, and all minting, withdrawal, and integration operations continue normally, with no action required from users.
Security analysts stressed that this was module-authorization abuse specific to one Safe, not a vulnerability in Safe’s core contracts or owner keys. The incident nonetheless highlights a persistent risk for smart contract wallet users: Safe’s core has never suffered a direct protocol exploit, but users have repeatedly lost funds through compromised infrastructure and vulnerable third-party extensions, including over $2 million stolen in address-poisoning attacks affecting 21 Safe users in 2023.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



