An Ethereum-based Gnosis Safe wallet lost approximately 2,900 rsETH worth USD 7.8 million on September 15 after an attacker exploited authorization weaknesses in a custom module. Security researchers stressed that Safe’s core contracts and Kelp DAO’s rsETH contracts were not compromised.
Custom Module Opened Attack Path
The affected wallet held about USD 7.73 million in rsETH-related assets before the exploit. Researchers traced the vulnerability to an authorized custom module and helper contract used to automate transactions.
The module’s access controls allowed external calls to execute through permissions already granted by the Safe. Bitquery said no owner key was stolen and the Safe processed module calls according to its existing permissions.
The attacker used the exposed route to move roughly 2,900 aETH from the Safe and convert the Aave-wrapped position into transferable rsETH.
MEV Bot Front-Runs Attacker
The original attacker did not ultimately capture most assets. An automated MEV searcher called ‘Yoink’ detected the exploit transaction and executed first in Ethereum block 25,980,525.
According to Bitquery, 2,882.37 rsETH moved to a separate address, while 17.63 rsETH was sold for approximately 18.95 ETH. Reports estimated Yoink paid around USD 46,000-USD 47,000 for priority transaction placement.
Blockaid described the incident as “module-authorization abuse on that Safe, not a Safe core / owner-key bug.”
Kelp DAO Restricts Receiving Wallet
Kelp DAO responded by temporarily pausing the address holding most intercepted rsETH for 24 hours.
“This is a precautionary, wallet-level measure only. Kelp contracts are safe, rsETH remains fully backed,” Kelp said, adding that minting, withdrawals and integrations continued operating normally.
The restriction prevented rsETH from moving through the targeted address while investigators reviewed the incident.
DeFi Permissions Remain Critical
The incident demonstrates how third-party modules can weaken otherwise secure multisignature wallets. Automated modules offer convenience for trading and DeFi strategies, but broad permissions can create attack paths when authorization logic fails.
For users and protocols, reviewing approved modules, limiting permissions and auditing helper contracts remain important safeguards. The USD 7.8 million incident shows that wallet security depends not only on core contracts but also on every authorized component connected to them.
Also Read: Gujarat Police Busts Interstate Bomb Threat Email Network with Bangladesh Crypto Links
Disclaimer : Crypto News India does not recommend that any cryptocurrency should be bought, sold, or held by you. Do conduct your own due diligence and consult your financial advisor before making any investment decisions.
