
Safe wallet loses $7.73M in rsETH exploit
- An Ethereum Safe wallet has lost about $7.73 million in rsETH through an exploit involving an authorised custom module.
- The attack has targeted roughly 2,900 rsETH, while an MEV bot has intercepted the extracted assets.
- Security researchers have linked the incident to a public multicall and an attacker-controlled Uniswap v4 hook.
An Ethereum Safe wallet has lost about $7.73 million in rsETH after an attacker exploited an authorised custom module.
The attacker has used a public Keeper Multicall to route the wallet's custom Uniswap v4 liquidity module towards an attacker-controlled hook pool.
The exploit has not involved a compromise of Safe's core contracts, with security analysis instead pointing to the wallet's authorised module and its execution path.
The attack has affected about 2,900 rsETH, which the module has converted from aEthrsETH before the assets moved through the attacker-controlled pool.
An MEV bot named Yoink has front-run the attacker's extraction transaction, moving the assets within the same block, while Kelp DAO has paused the receiving address for 24 hours.
The affected position has involved rsETH, a liquid restaking token issued by Kelp DAO, with the wallet holding the assets through Aave's interest-bearing aEthrsETH position.
Kelp DAO has said its core contracts remain secure and rsETH remains fully collateralised, while the incident has highlighted risks linked to custom modules and delegated smart-contract execution.

