Ethereum Wallet Exploit Drains $7.8 Million in rsETH Tokens, Security Firms Warn

A flawed authorisation check allowed an attacker to redirect a Safe wallet’s trading module to a malicious liquidity pool.

Advertisement
Written by Rahul Dhingra, Edited by Rohan Pal | Updated: 15 September 2026 18:52 IST
Highlights
  • The attacker redirected a Safe module through a public keeper function
  • Yoink spent about $47,000 to front-run the transaction
  • Kelp DAO temporarily paused an address that received the rsETH

Kelp DAO temporarily restricted an address linked to the suspicious rsETH activity

Photo Credit: Unsplash/Shubham Dhage

A hacker exploited a Gnosis Safe wallet on the Ethereum network, taking out about 2,900 rsETH tokens valued at around $7.8 million (roughly Rs. 74.7 crore). The transaction was front-run by an automated bot called “yoink,” according to reports from security firms BlockSec, Blockaid, and SlowMist. The wallet belonging to the victim was configured in such a way that the helper contract could perform transactions on its behalf. The purpose of the helper was to confirm whether the caller had authorisation. However, according to SlowMist and BlockSec, any address could get authorisation as long as it claimed to be the helper itself.

Malicious Hook Pool Used to Drain Restaked ETH Tokens

The attacker initially made use of a public keeper multicall function to redirect the wallet's custom Uniswap v4 Safe module to a malicious Hook pool. In turn, the module was responsible for unwrapping the wallet's aEthrsETH, which was essentially an Aave-wrapped version of restaked ETH into rsETH tokens. The attacker tried to extract those tokens through the malicious pool. 

Advertisement

:rotating_light:Blockaid exploit detection system detected an exploit on an unidentified user's Safe on Ethereum.
~$7.73M confirmed rsETH loss so far.
An attacker used a public keeper multicall to drive a custom Uni V4 LP Safe module into an attacker-created hooked pool; the hook unwrapped…

— Blockaid (@blockaid_) September 15, 2026

Subsequently, the attacker poured around 2,900 rsETH into a trading pool that was created within minutes using a useless token known as the Permissionless Attacker Token. The wallet was left with a receipt that had no value. The Yoink bot made an investment of about $47,000 (roughly Rs. 45 lakh) to cut in line and got the tokens, sending 2,882 rsETH to a separate address. 

Advertisement

“The root cause was a flawed authorisation check in the Multicall contract," AstraSec said in a post on X. The other security firms thought that the problem lay in the component trusted by the wallet holder rather than in the fundamental contracts of Safe. Kelp DAO, the issuer of rsETH, claims that their contracts are secure and rsETH is fully collateralised.

“We've detected potential suspicious activity on an address that received rsETH a few hours ago,” KelpDAO wrote on X. “Out of an abundance of caution, we've placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in or out of it.”

Advertisement

Since rsETH is a liquid staking asset, the mere possession of $7.8 million (roughly Rs. 74.7 crore) worth of such by the wallet does not imply that Kelp DAO is sitting on $7.8 million (roughly Rs. 74.7 crore) worth of the same token, which it can easily retrieve. If the stolen rsETH still resides within an address under the control of Yoink, recovery will usually entail freezing, blacklisting, recovering, or other restrictions on the assets, assuming the nature of the token allows for that.

As per another report by a blockchain security firm, PeckShield, the number of crypto hacks witnessed a sharp increase in August, even though the amount of money lost declined by almost half from July levels. On September 1, the security firm said it had detected 50 attacks in August. This is a 67 percent increase from the 30 cases reported in July. The numbers provided by PeckShield may differ as projects continue to investigate transactions, freeze assets, and recover funds. 

Advertisement

Cryptocurrency is an unregulated digital currency, not a legal tender and subject to market risks. The information provided in the article is not intended to be and does not constitute financial advice, trading advice or any other advice or recommendation of any sort offered or endorsed by NDTV. NDTV shall not be responsible for any loss arising from any investment based on any perceived recommendation, forecast or any other information contained in the article.

 

Also seeCryptocurrency Prices across Indian exchanges

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X10 Pro Max Among First Phones to Launch With 2nm Dimensity 9600 Pro
  2. Redmi Note 17 Pro Series With Up to 10,000mAh Battery Debuts in India
  3. Vivo V80 India Launch Officially Confirmed, Design Teased
  1. Ethereum Wallet Exploit Drains $7.8 Million in rsETH Tokens, Security Firms Warn
  2. Vivo Buds Clip Launch Date Confirmed for September 21, Colour Options Revealed
  3. Oppo Find X10 Pro Max to Be Among First Phones With MediaTek's 2nm Dimensity 9600 Pro Chip
  4. Delta Exchange Lands Global Sponsor Slot for India-Afghanistan T20I Series
  5. Apple iCloud+ Plans in India Now Include Apple TV and Arcade at No Extra Cost
  6. Googlebook Laptops to Open for Pre-Orders on September 21, Google Confirms
  7. CoinEx Set to Close Exchange After Almost Nine Years in Operation
  8. iQOO 16 Launch Date Confirmed for September 29 in China, Three Colours Revealed
  9. Mac Mini M6 Geekbench Listing Reportedly Reveals Performance Gains Over M5 Chip
  10. Vivo V80, S2 FE Reportedly Get BIS Certification Hinting at Imminent India Launch; X500 Pro Max Appears on NBTC
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.