$7.73M rsETH Lost in Ethereum Safe Exploit

An Ethereum Safe wallet lost $7.73 million in rsETH after an authorised module was exploited through a public multicall and attacker-controlled liquidity pool.

$7.73M rsETH Lost in Ethereum Safe Exploit
$7.73M rsETH Lost in Ethereum Safe Exploit

An Ethereum smart contract wallet lost over $7.73 million (2,882 rsETH) on September 15 as a result of a fault in an authorised third-party support module. A public keeper multicall and a modified liquidity pool were used by the attacker to initiate the drain. Unexpectedly, though, a MEV bot called "Yoink" front-ran the transaction in the public mempool. Before Kelp DAO intervened to freeze the target address, Yoink paid almost $47,000 in priority fees to seize the funds.

The Safe Was Not Directly Compromised

The intrusion's focus point was target address 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8, which secured a large rsETH staking reserve. Instead of using Safe base code, security auditors found an error in an auxiliary smart contract that pointed directly to account owner-approved unique integration modules that automated decentralised finance exposure.

During the event, base multisig contracts functioned perfectly. The companion tool's secondary execution rights were the only source of asset exposure. Unauthorised fund transfer was made possible by improper caller validation within the helper contract, as proven by further technical breakdowns released by BlockSec and SlowMist.

Blockaid was the source of the preliminary breach insight, which confirmed the total asset drainage of 2882 rsETH, or around $7.73 million.

A Public Multicall Opened the Way

A public keeper multicall route directly into the approved liquidity integration was the first step in the execution process. Malicious inputs forced a reliable component to initiate arbitrary balance actions outside of standard administrative boundaries by avoiding account keys and multisig authentication requirements.

The auxiliary tool kept its connections to the Uniswap v4 system intact. To influence balance accounting, the exploit logic deployed an external pool with custom hook logic. Aave collateralised yield tokens were represented by underlying equity in aEthrsETH. By unwinding that interest-bearing deposit back into its native liquid form, manipulation placed raw tokens available for withdrawal.

The last transaction states that the liquid backing completely disappeared from the account, leaving the depository with an empty liquidity position token with no actual value.

Yoink Front-Ran the Attacker

The original culprit never obtained custody of the depleted tokens.

When Yoink, an MEV bot, found the broadcast payload within Ethereum mempool channels, it quickly submitted a competing transaction with priority fee escalations over $47,000. The entire 2882 rsETH reward was diverted into different infrastructure since block builders were compelled to order the bot bundle first due to the heavy bidding.

This transaction totally preempted planned settlement pathways. Automated arbitrage machinery claimed ultimate custody before primary execution reached terminal block state, depriving depositors of collateral regardless of recipient identity, despite the fact that criminal actors created the original protocol bypass.

Kelp DAO Paused the Receiving Address

During preliminary triage, KelpDAO quickly located the destination ledger containing the misdirected funds and used administrative rights to stop token transactions associated with that target for twenty-four hours. Throughout the event, project coordinators verified that core protocol contracts and base staking reserves remained completely solvent.

Instead of taking distributed funds across decentralised mixers, protocol contributors obtained an instant focal coordinate for emergency isolation since automated infrastructure collected the assets at a single trackable location.

The hack brings to light the architectural risks associated with modular smart accounts. The approval of auxiliary plugins with unrestricted settlement authority created direct attack paths, demonstrating that account security depended solely on the weakest peripheral dependency in the execution path, even when foundational account layers resisted direct compromise.


If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.

To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.

Related Articles

  1. Mislav Javor Joins Ethlabs to Build Ethereum
  2. Platåberget Testnet Brings Glamsterdam Closer to Mainnet
  3. Vitalik’s Bitcoin-Inspired Plan for Ethereum
  4. EIPsInsight Just Changed How You Track Ethereum Upgrades
  5. Why Institutions Are Suddenly Taking Ethereum Seriously?

To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.

Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.


Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.

To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.

To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.

If you’d like to support our work, share the content and consider donating at avarch.eth.

Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.

Sponsored
ETHShala

Understand Ethereum. Shape the Future — learn EIPs with ETHShala.

Inviting Web3 projects to partner with EtherWorld and increase visibility across the Ethereum ecosystem.

EIPs Insight

Track Ethereum protocol upgrades, EIPs & governance — all in one place.

EtherWorld.co × Avarch

Gain hands-on Web3 experience with our internship program.

Subscribe to join the discussion.

Please create an account to become a member and join the discussion.

Already have an account? Sign in

Sign up for EtherWorld.co newsletters.

Stay up to date with curated collection of our top stories.

Please check your inbox and confirm. Something went wrong. Please try again.
0/5 free articles read this week
Sign up free