Industry News

Custom Safe Wallet Module Flaw Leads to $7.8 Million rsETH Theft

CoinPedia · 15 Sept 2026
Key Takeaway Businesses using custom smart contract modules or third-party wallet extensions should have them independently audited for access control flaws before granting them authority over funds.

An Ethereum wallet has lost around $7.8 million worth of rsETH after attackers exploited a custom Safe module connected to a Uniswap v4 liquidity pool, rather than a flaw in Kelp DAO's core rsETH contracts. Security firm Blockaid found that the module contained a public entry point which accepted attacker-controlled data and used a risky code execution method without proper access checks, allowing an outsider to act with the wallet's own authorised permissions.

The attacker redirected the wallet's Safe module to a malicious liquidity pool and unpacked wrapped restaked ETH into raw rsETH in an attempt to steal it. However, before the attacker could complete the theft, an automated trading bot known as 'yoink' spotted the pending transaction in Ethereum's public transaction queue and front-ran it, capturing the entire $7.8 million for itself instead.

Kelp DAO has said its core protocol remains secure and that the rsETH pool is fully collateralized, and it has paused rsETH transfers for 24 hours while it investigates. Recovering the funds may depend on whether the token's design allows the stolen assets to be frozen or restricted.

cryptocurrency smart contract exploit blockchain security

Summarised by CISO AI from CoinPedia. We link back to every original so you can read it yourself.