An Ethereum wallet holding leveraged rsETH has lost around $7.8 million after an attacker exploited a custom Safe module linked to a Uniswap v4 liquidity pool. The incident happened on September 15, 2026, but security researchers said the attack did not come from a flaw in Kelp DAO’s core rsETH contracts.
Here’s how the exploit actually happen.
Custom Safe Module Exposed Wallet to Attack
Blockchain security firm Blockaid identified the attack and traced it to a custom Uniswap v4 LP Safe module used by the affected Gnosis Safe wallet.
The wallet at 0x40E93…7AbA8 held about $7.73 million worth of rsETH before the attack.
According to the security analysis, the module had a public entry point that accepted caller-controlled data and used DELEGATECALL without proper access checks.
Because the module was already authorized by the Safe, an outside attacker could use that entrypoint to execute code inside the wallet’s own context.
This gave the attacker control over the wallet’s assets.
How rsETH Exploit Happen?
The attacker first used a public keeper multicall function to redirect the wallet’s custom Uniswap v4 Safe module toward a malicious Hook pool.
The module then unpacked the wallet’s aEthrsETH, an Aave-wrapped version of restaked ETH, into raw rsETH. The attacker attempted to extract those tokens through the malicious pool.
Perhaps, the original attacker did not get the stolen funds.
Why!
Because the attacker’s transaction entered Ethereum’s mempool, where an MEV bot known as “yoink” detected and front-ran the transaction and captured the entire roughly $7.8 million worth of rsETH for itself.
Can Kelp just withdraw the $7.8M from rsETH?
Not necessarily. As rsETH is a liquid restaking token. The fact that the wallet held $7.8M worth of rsETH does not mean Kelp DAO has a $7.8M pile of the same tokens that it can simply take back.
If the stolen rsETH remains in an address controlled by Yoink, recovery would generally require freezing, blacklisting, recovering, or otherwise restricting those assets, if the token’s design and applicable controls allow it.
Kelp DAO Says Core rsETH Contracts Are Safe
Meanwhile Kelp DAO team has responded by temporarily pausing rsETH transfers for 24 hours to isolate the affected funds.
The team said its core smart contracts remained secure and that the rsETH pool was fully collateralized. Normal minting, redemptions, and other DeFi integrations continued to operate.
Was this writing helpful?
Story Ends Here
Trust with CoinPedia:
Investment Disclaimer:
All opinions and insights shared represent the author’s own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.
Sponsored and Advertisements:
Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.
Read the Next News