$7.73M rsETH Lost in Ethereum Safe Exploit
An Ethereum Safe wallet lost $7.73 million in rsETH after an authorised module was exploited through a public multicall and attacker-controlled liquidity pool.
An Ethereum smart contract wallet lost over $7.73 million (2,882 rsETH) on September 15 as a result of a fault in an authorised third-party support module. A public keeper multicall and a modified liquidity pool were used by the attacker to initiate the drain. Unexpectedly, though, a MEV bot called "Yoink" front-ran the transaction in the public mempool. Before Kelp DAO intervened to freeze the target address, Yoink paid almost $47,000 in priority fees to seize the funds.
The Safe Was Not Directly Compromised
The intrusion's focus point was target address 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8, which secured a large rsETH staking reserve. Instead of using Safe base code, security auditors found an error in an auxiliary smart contract that pointed directly to account owner-approved unique integration modules that automated decentralised finance exposure.
During the event, base multisig contracts functioned perfectly. The companion tool's secondary execution rights were the only source of asset exposure. Unauthorised fund transfer was made possible by improper caller validation within the helper contract, as proven by further technical breakdowns released by BlockSec and SlowMist.
Blockaid was the source of the preliminary breach insight, which confirmed the total asset drainage of 2882 rsETH, or around $7.73 million.
🚨Blockaid exploit detection system detected an exploit on an unidentified user's Safe on Ethereum.
— Blockaid (@blockaid_) September 15, 2026
~$7.73M confirmed rsETH loss so far.
An attacker used a public keeper multicall to drive a custom Uni V4 LP Safe module into an attacker-created hooked pool; the hook unwrapped…
A Public Multicall Opened the Way
A public keeper multicall route directly into the approved liquidity integration was the first step in the execution process. Malicious inputs forced a reliable component to initiate arbitrary balance actions outside of standard administrative boundaries by avoiding account keys and multisig authentication requirements.
The auxiliary tool kept its connections to the Uniswap v4 system intact. To influence balance accounting, the exploit logic deployed an external pool with custom hook logic. Aave collateralised yield tokens were represented by underlying equity in aEthrsETH. By unwinding that interest-bearing deposit back into its native liquid form, manipulation placed raw tokens available for withdrawal.
The last transaction states that the liquid backing completely disappeared from the account, leaving the depository with an empty liquidity position token with no actual value.
Yoink Front-Ran the Attacker
The original culprit never obtained custody of the depleted tokens.
When Yoink, an MEV bot, found the broadcast payload within Ethereum mempool channels, it quickly submitted a competing transaction with priority fee escalations over $47,000. The entire 2882 rsETH reward was diverted into different infrastructure since block builders were compelled to order the bot bundle first due to the heavy bidding.
This transaction totally preempted planned settlement pathways. Automated arbitrage machinery claimed ultimate custody before primary execution reached terminal block state, depriving depositors of collateral regardless of recipient identity, despite the fact that criminal actors created the original protocol bypass.
Kelp DAO Paused the Receiving Address
During preliminary triage, KelpDAO quickly located the destination ledger containing the misdirected funds and used administrative rights to stop token transactions associated with that target for twenty-four hours. Throughout the event, project coordinators verified that core protocol contracts and base staking reserves remained completely solvent.
We've detected potential suspicious activity on an the address (0xc70f00cd7e461686b04b0e912e309beca8b80ea0) that received rsETH a few hours ago.
— Kelp (@KelpDAO) September 15, 2026
Out of an abundance of caution, we've placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in…
Instead of taking distributed funds across decentralised mixers, protocol contributors obtained an instant focal coordinate for emergency isolation since automated infrastructure collected the assets at a single trackable location.
The hack brings to light the architectural risks associated with modular smart accounts. The approval of auxiliary plugins with unrestricted settlement authority created direct attack paths, demonstrating that account security depended solely on the weakest peripheral dependency in the execution path, even when foundational account layers resisted direct compromise.
If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- Mislav Javor Joins Ethlabs to Build Ethereum
- Platåberget Testnet Brings Glamsterdam Closer to Mainnet
- Vitalik’s Bitcoin-Inspired Plan for Ethereum
- EIPsInsight Just Changed How You Track Ethereum Upgrades
- Why Institutions Are Suddenly Taking Ethereum Seriously?
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.