News Report Technology
September 15, 2026

Exploit Drains $7.8M In rsETH From User’s Safe Wallet Through Compromised Strategy Executor

Exploit Drains $7.8M In rsETH From User’s Safe Wallet Through Compromised Strategy Executor

Blockchain security firms Blockaid, PeckShield, and BlockSec have confirmed an exploit that drained approximately $7.8 million worth of rsETH, around 2,900 tokens, from a Gnosis Safe wallet on Ethereum. The incident began at 04:38 UTC with a transaction that moved the bulk of the funds, followed by several smaller transactions over the next hour totaling an additional ~$160,000, according to the firms’ reports.

The root cause was a flawed authorization check in the executor contract, identified by analysts as address 0x4f0055926c839D1d960a82CBF84E2eE933958ebC. 

The targeted Safe, belonging to a large holder of leveraged rsETH, relied on a whitelisted strategy executor module that exposed a recipe entrypoint. This entrypoint forwarded fully caller-supplied calldata into the Safe’s execTransactionFromModuleReturnData function using operation=1 (DELEGATECALL) without gating the external caller. Setting the supplied contract parameter to the executor’s own address passed validation, meaning anyone who could reach the entrypoint could execute arbitrary code within the Safe’s own context — effectively gaining full control over its assets.

The attacker used a public keeper multicall to route the authorized Uni V4 LP Safe module into an attacker-created hooked Uniswap V4 pool, executing via Permit2 and the PositionManager. The attacker had deployed a worthless token dubbed the “Permissionless Attacker Token” (PAT) and supplied roughly 2,900 aEthrsETH as liquidity against it. A custom hook in the pool unwrapped the aEthrsETH into rsETH and siphoned it out of the Safe, which was left holding a valueless LP NFT.

MEV Bot Front-Runs Attack; KelpDAO Imposes Temporary Pause

Notably, the original attack transaction never reached its intended beneficiary. The attacker launched the exploit directly into the public mempool, where it was front-run by an MEV bot named “yoink,” which captured the entire ~2,882 rsETH — worth roughly $7.8 million — and routed it to address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. In effect, a maximal extractable value bot, not the attacker, walked away with the stolen funds.

In response, KelpDAO announced it had detected suspicious activity on the receiving address and placed it under a precautionary 24-hour pause, during which rsETH cannot move in or out. The team stated it is working with security experts on the investigation, and emphasized that the measure is wallet-level only: Kelp contracts remain safe, rsETH stays fully backed, and all minting, withdrawal, and integration operations continue normally, with no action required from users.

Security analysts stressed that this was module-authorization abuse specific to one Safe, not a vulnerability in Safe’s core contracts or owner keys. The incident nonetheless highlights a persistent risk for smart contract wallet users: Safe’s core has never suffered a direct protocol exploit, but users have repeatedly lost funds through compromised infrastructure and vulnerable third-party extensions,  including over $2 million stolen in address-poisoning attacks affecting 21 Safe users in 2023.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles
Alisa Davidson
Alisa Davidson

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

Hot Stories
Join Our Newsletter.
Latest News

Shufti, Jumio, Sumsub, And Beyond: Top 6 Identity Verification And Compliance Platforms To Know In 2026

Shufti, Sumsub, Incode, Veriff, Persona and Jumio compared on compliance lifecycle coverage, pricing transparency and fraud detection ...

Know More

2026 AI Market Claims Vs SEC Fillings: Linkmate Analysis

Is the AI market really all just PR talk or there's a deeper math going on in ...

Know More
Read More
Read more
Bitcoin’s Post-Quantum Roadmap Takes Shape Around P2MR And SHRINCS, But Key Gaps Remain
News Report Technology
Bitcoin’s Post-Quantum Roadmap Takes Shape Around P2MR And SHRINCS, But Key Gaps Remain
September 15, 2026
Siri AI Debuts In English Beta Across Apple’s 2027 Platforms, Excluding EU And China
News Report Technology
Siri AI Debuts In English Beta Across Apple’s 2027 Platforms, Excluding EU And China
September 15, 2026
Top 10 AI Tools Detecting Wash Trading And Market Abuse In 2026
Top Lists Technology
Top 10 AI Tools Detecting Wash Trading And Market Abuse In 2026
September 14, 2026
Top 10 AI Companies Developing Large Language Models For Crypto
Top Lists Technology
Top 10 AI Companies Developing Large Language Models For Crypto
September 14, 2026