Industry News

Kelp DAO Freezes Deposits After $7.8M Gnosis Wallet Exploit

Cryptopolitan · 15 Sept 2026
Key Takeaway Businesses using DeFi or crypto wallets should regularly review which smart contract modules or third-party integrations have standing permissions, since even 'trusted' automation features can become attack entry points.

A Gnosis Safe wallet was exploited on September 15 for roughly $7.73 million worth of rsETH, according to Blockaid data. The funds, equivalent to 2,153 ETH, were drained in a single transaction and split across multiple wallets, with the tokens kept as rsETH rather than converted to ETH for further laundering.

The attack targeted a whitelisted Safe module that had been trusted to automate DeFi strategy execution. Because the module was already authorised, an attacker was able to call it without needing extra permissions, turning a convenience feature into the entry point for the theft. Adding to the complexity, an MEV bot called Yoink front-ran the exploiter within the same block and captured much of the ETH before it could be withdrawn, though most of those funds remain locked as rsETH.

Kelp DAO flagged the bot's destination address and placed it under a temporary 24-hour pause, halting rsETH transfers in or out as a precaution. This is one of several large DeFi exploits this month, with total losses in September already exceeding $326 million across the sector, according to DeFi Llama.

DeFi cryptocurrency exploit smart contract security

Summarised by CISO AI from Cryptopolitan. We link back to every original so you can read it yourself.