Edited by Editor-in-Chief, The Indus Pulse 15 Sept 2026, 09:46 PM 2 min readtech

Ethereum Safe Wallet Exploit Drains 2,900 rsETH Tokens Valued at $7.8 Million

An attacker drained approximately 2,900 rsETH tokens valued at roughly $7.8 million from an Ethereum-based Gnosis Safe wallet after exploiting a custom Uniswap v4 liquidity pool module. Blockchain security firms Blockaid, BlockSec, SlowMist, and AstraSec identified the exploit on September 15, 2026, noting that the vulnerability stemmed from a flawed authorization check within a custom Safe module rather than any fundamental flaw in Kelp DAO core contracts.
The compromised wallet held about $7.73 million in restaked Ethereum assets before the attacker leveraged a public keeper multicall function. This function redirected the wallet custom Uniswap v4 Safe module toward an attacker-created hooked pool, which unwrapped the wallet Aave-wrapped restaked ETH, known as aEthrsETH, into raw rsETH tokens.

MEV Bot Front-Runs Attacker to Capture Funds

Although the initial exploit successfully diverted the assets, the attacker did not retain the stolen capital. An automated Maximum Extractable Value bot known as yoink detected the transaction in Ethereum memory pool and front-ran it by spending about $47,000 to cut in line. The bot captured the entire cache of stolen tokens, sending 2,882 rsETH to a separate address.
Security analysts explained that the targeted wallet was configured so that a helper contract could execute transactions on its behalf after confirming caller authorization. However, SlowMist and BlockSec reported that any address could bypass these safeguards by falsely claiming to be the helper contract itself. AstraSec added that the multicall contract suffered from a flawed authorization check that permitted caller-controlled data through delegate call operations without proper access restrictions.

Kelp DAO Imposes Temporary Transfer Restrictions

In response to the incident, liquid staking issuer Kelp DAO placed the suspicious address that received the rsETH under a temporary 24-hour pause to isolate the affected funds and prevent further movement. The organization emphasized that its core smart contracts remain secure and fully collateralized, while normal minting, redemptions, and broader decentralized finance integrations continue operating without disruption.
Because rsETH functions as a liquid staking token, possessing $7.8 million worth of the asset does not equate to holding an equivalent pile of liquid reserves that can be retrieved automatically. Blockchain security firm PeckShield noted that the exploit occurs amid a broader surge in web3 security incidents, having recorded 50 crypto attacks in August 2026, representing a 67 percent increase compared to 30 cases in July, even though total funds lost across the sector declined during that period.
The Indus Pulse is committed to accuracy and transparency.