Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerDerivativesETF FlowsCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

Ethereum Safe Wallet Loses $7.73M in rsETH Through Malicious Module and Uniswap V4 Hook

bullish:

0

bearish:

0

Ethereum Safe Wallet Loses $7.73M in rsETH Through Malicious Module and Uniswap V4 Hook

An Ethereum user lost approximately $7.73 million in rsETH after an attacker used a Safe module execution path to redirect assets through an attacker-controlled Uniswap v4 liquidity pool.

The affected Safe address was targeted early September 15, with security monitoring identifying two transactions responsible for the loss. The available evidence points to the wallet’s custom module and its interaction with a malicious hook rather than a vulnerability in the core Safe smart-account contracts.

Custom Module Routed Assets Into Malicious Pool

The attack used a public keeper multicall to invoke a custom Uni V4 LP Safe module attached to the account. The execution directed liquidity into a Uniswap v4 pool created with an attacker-controlled hook, giving the malicious routing logic access to assets involved in the position.

The hook then converted the victim’s aEthrsETH position into transferable rsETH. aEthrsETH represents rsETH supplied to Aave, meaning the attacker needed to move the position out of its Aave receipt-token form before the underlying rsETH could be extracted.

Safe module architecture allows authorized extensions to execute transactions independently from the normal multisignature flow. Modules can automate complex DeFi operations, but Safe warns that they are security-critical because an enabled malicious or vulnerable module can execute arbitrary transactions from an account.

The attack did not compromise Safe’s core multisig contracts, signer keys or Ethereum itself. The identified failure path involved the account’s custom module and an attacker-controlled Uniswap v4 hook. A similar separation emerged when a SquidRouterModule exploit drained 86 Safe accounts across Ethereum and Base in May while leaving the underlying Safe contracts outside the identified failure path.

MEV Bot Captures the Extraction

The attack transaction was intercepted within the block by an MEV operation associated with the address Etherscan labels MEV Frontrunner Yoink.

The bot front-ran the original extraction and captured the profitable transaction path before the attacker could complete it as submitted. The victim still lost the rsETH because the underlying malicious execution succeeded, while the ordering of transactions changed which external address ultimately captured much of the extracted value.

The Safe was left with only a liquidity-position NFT from the malicious pool instead of the rsETH-backed position it held before the transactions.

rsETH Returns to Security Focus

rsETH is Kelp DAO’s liquid restaking token and remains integrated across Ethereum lending and liquidity markets. Its use inside Aave created the aEthrsETH collateral involved in the latest wallet drain.

Kelp’s token has already been through a major security disruption this year after an April Kelp DAO exploit released roughly $292 million in rsETH from cross-chain infrastructure and created substantial downstream exposure across DeFi lending markets.

The September 15 loss is a separate event. Current evidence centers on the individual Safe’s module execution, the attacker-controlled Uniswap v4 hook and the resulting conversion of the wallet’s Aave-backed rsETH position. No broader compromise of Safe, Aave, Kelp DAO or the rsETH token contract has been established.

The post Ethereum Safe Wallet Loses $7.73M in rsETH Through Malicious Module and Uniswap V4 Hook appeared first on Crypto Adventure.

bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.