A flawed authorisation check allowed an attacker to redirect a Safe wallet’s trading module to a malicious liquidity pool.
Photo Credit: Unsplash/Shubham Dhage
Kelp DAO temporarily restricted an address linked to the suspicious rsETH activity
A hacker exploited a Gnosis Safe wallet on the Ethereum network, taking out about 2,900 rsETH tokens valued at around $7.8 million (roughly Rs. 74.7 crore). The transaction was front-run by an automated bot called “yoink,” according to reports from security firms BlockSec, Blockaid, and SlowMist. The wallet belonging to the victim was configured in such a way that the helper contract could perform transactions on its behalf. The purpose of the helper was to confirm whether the caller had authorisation. However, according to SlowMist and BlockSec, any address could get authorisation as long as it claimed to be the helper itself.
The attacker initially made use of a public keeper multicall function to redirect the wallet's custom Uniswap v4 Safe module to a malicious Hook pool. In turn, the module was responsible for unwrapping the wallet's aEthrsETH, which was essentially an Aave-wrapped version of restaked ETH into rsETH tokens. The attacker tried to extract those tokens through the malicious pool.
:rotating_light:Blockaid exploit detection system detected an exploit on an unidentified user's Safe on Ethereum.
— Blockaid (@blockaid_) September 15, 2026
~$7.73M confirmed rsETH loss so far.
An attacker used a public keeper multicall to drive a custom Uni V4 LP Safe module into an attacker-created hooked pool; the hook unwrapped…
Subsequently, the attacker poured around 2,900 rsETH into a trading pool that was created within minutes using a useless token known as the Permissionless Attacker Token. The wallet was left with a receipt that had no value. The Yoink bot made an investment of about $47,000 (roughly Rs. 45 lakh) to cut in line and got the tokens, sending 2,882 rsETH to a separate address.
“The root cause was a flawed authorisation check in the Multicall contract," AstraSec said in a post on X. The other security firms thought that the problem lay in the component trusted by the wallet holder rather than in the fundamental contracts of Safe. Kelp DAO, the issuer of rsETH, claims that their contracts are secure and rsETH is fully collateralised.
“We've detected potential suspicious activity on an address that received rsETH a few hours ago,” KelpDAO wrote on X. “Out of an abundance of caution, we've placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in or out of it.”
Since rsETH is a liquid staking asset, the mere possession of $7.8 million (roughly Rs. 74.7 crore) worth of such by the wallet does not imply that Kelp DAO is sitting on $7.8 million (roughly Rs. 74.7 crore) worth of the same token, which it can easily retrieve. If the stolen rsETH still resides within an address under the control of Yoink, recovery will usually entail freezing, blacklisting, recovering, or other restrictions on the assets, assuming the nature of the token allows for that.
As per another report by a blockchain security firm, PeckShield, the number of crypto hacks witnessed a sharp increase in August, even though the amount of money lost declined by almost half from July levels. On September 1, the security firm said it had detected 50 attacks in August. This is a 67 percent increase from the 30 cases reported in July. The numbers provided by PeckShield may differ as projects continue to investigate transactions, freeze assets, and recover funds.
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.
Apple Watch Series 12
Starts from ₹56,900
Samsung Galaxy Watch Ultra 2
Starts from ₹64,999
Samsung Galaxy Watch 9 (44mm, LTE)
Starts from ₹41,999
Samsung Galaxy Watch 9 (40mm, LTE)
Starts from ₹38,999
Samsung Galaxy Watch 9 (40mm)
Starts from ₹37,999
Samsung Galaxy Watch 9 (44mm)
Starts from ₹40,999
Vivo Buds Clip Launch Date Confirmed for September 21, Colour Options Revealed