Wednesday, September 16, 2026

Gnosis Safe Exploit Drains $7.8M in rsETH on Ethereum

Neon cyber illustration of a Gnosis Safe vault under a flawed helper contract attack, with a front-running bot siphoning rsETH amid glow, bokeh.

An Ethereum Safe wallet lost control of roughly 2,900 rsETH worth about $7.8 million after an attacker exploited a flawed authorization path in a third-party module. The attempted theft was then front-run by an MEV searcher known as Yoink, which captured most of the rsETH before the original attacker could receive it. Security researchers have stressed that Safe’s core smart contracts were not compromised.

The main extraction can be seen in the on-chain transaction recorded by Etherscan. Yoink’s transaction landed first in Ethereum block 25980525 and ultimately routed 2,882.37 rsETH to a separate address, while another 17.63 rsETH was exchanged through Uniswap v4. The bot paid roughly $46,000-$47,000 for priority execution.

Authorization Flaw Exposed the Safe

Researchers traced the vulnerability to infrastructure that the wallet owner had already authorized. A Multicall-style helper could be manipulated into treating an external caller as authorized when the helper itself was supplied as the execution target, giving the attacker a path into a trusted Safe module without obtaining the wallet owners’ signatures.

The affected Safe held its position as aEthrsETH, the Aave representation of deposited rsETH. The exploit path used the Safe’s existing module authority to move the position into a deliberately constructed liquidity operation involving a worthless Permissionless Attacker Token, or PAT, after which the aEthrsETH could be withdrawn into transferable rsETH. More detailed transaction tracing found no evidence that a custom malicious Uniswap v4 hook was required for the attack.

Yoink was able to copy the profitable execution after the attacker exposed it through Ethereum’s public transaction flow. The MEV bot secured transaction index zero in the block and reached the vulnerable execution path before the original exploiter, effectively redirecting the largest portion of the attempted theft to itself.

Kelp DAO Restricts the Receiving Address

Kelp DAO responded by placing a temporary 24-hour restriction on the address that received the bulk of the captured rsETH. The measure prevented approximately 2,882 rsETH from moving through that wallet while the incident was reviewed, while Kelp said its core contracts remained secure and rsETH continued to be fully collateralized. Normal minting, redemptions and DeFi integrations were not broadly paused.

The incident reinforces the security risk created when otherwise secure multisig wallets grant broad authority to external modules. Similar weaknesses in third-party components have already produced losses involving Safe-connected infrastructure, highlighting how a wallet’s effective security boundary can extend well beyond its core contracts once automated modules receive transaction authority.

Recovery remains unresolved. No publicly confirmed reimbursement agreement or return arrangement with the Yoink operator has been announced, and some rsETH was already converted before the receiving address was restricted. The immediate issue is whether the remaining 2,882.37 rsETH can be recovered and whether a formal post-mortem identifies additional safeguards for Safe modules using similar authorization patterns.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.