Industry News

Flawed Auto-Trading Add-On Leads to $7.8M Ethereum Wallet Drain

Crypto Economy · 15 Sept 2026
Key Takeaway Before connecting any automated trading or third-party contract to a business crypto wallet, have its permission logic independently audited, since a flaw there can bypass even a secure wallet's protections.

An attacker exploited a flawed authorization check in an auxiliary contract connected to a Gnosis Safe wallet, draining about 2,900 rsETH (Kelp DAO's liquid staking token), worth roughly $7.8 million, on the Ethereum network. Security firms BlockSec, Blockaid, SlowMist and AstraSec identified and confirmed the incident within hours.

The wallet owner had authorized an external contract to automatically execute trades, a common setup for automated trading strategies. Investigators found that this add-on contract's permission check was broken: rather than verifying the caller was genuinely authorized, it approved requests simply because they named the contract itself as the destination. This allowed the attacker to trigger unauthorized fund movements.

All four firms agreed the vulnerability sat in the external, user-added component rather than in Safe's core wallet software. This distinction matters because it shows that even secure multisig wallets can be compromised through third-party integrations the owner chooses to enable.

Summarised by CISO AI from Crypto Economy. We link back to every original so you can read it yourself.