DigitalMoneyBox Signal Desk
DigitalMoneyBox Crypto market intelligence
Browse sections
Security Unchained

A Bot Robbed the Hacker Who Drained $7.8 Million in rsETH From a Safe Wallet

An attacker drained about $7.8 million in rsETH from an Ethereum Safe wallet early Tuesday, then lost the payout to a bot that was watching the same block. The theft, first flagged by security firm Blockaid, moved roughl...

78 /100
Market signal

Watchlist

Published in the last two hours. Multiple named entities are involved.

A Bot Robbed the Hacker Who Drained $7.8 Million in rsETH From a Safe Wallet

An attacker drained about $7.8 million in rsETH from an Ethereum Safe wallet early Tuesday, then lost the payout to a bot that was watching the same block. The theft, first flagged by security firm Blockaid, moved roughly 2,900 rsETH out of a Gnosis Safe at 04:38 UTC. In the same block, a generalized MEV searcher known as Yoink front-ran the attacker’s own transaction, paying about $46,000 to the block’s builder to have its transaction ordered first, and walked away with the funds instead.

The wallet itself was never the weak point. Blockaid described the incident as “module-authorization abuse on that Safe, not a Safe core / owner-key bug,” and researchers at BlockSec, SlowMist and AstraSec traced the fault to the same spot: a Multicall helper the wallet’s owner had approved. The helper treated any call that pointed back at its own address as pre-authorized, so an outsider could push instructions through the module and have the Safe run them as if they were its own.

The Module Was the Backdoor

Safe multisigs let owners bolt on third-party modules that can move funds without collecting the usual signatures. Here, a custom Uniswap v4 liquidity module exposed an entrypoint that forwarded attacker-supplied instructions into the wallet. The attacker pointed it at a pool he controlled, unwrapped the wallet’s yield-bearing aEthrsETH into ordinary rsETH, and left behind worthless receipts. Safe’s own contracts did exactly what an authorized module told them to.

A Bot Beat the Attacker to It

Because the exploit transaction sat in the public mempool, Yoink saw it coming and executed first in the same block, capturing 2,882 rsETH and routing it to a fresh address. Restaking protocol Kelp DAO froze that address within two hours. “Out of an abundance of caution, we’ve placed that address under a temporary 24-hour pause,” the protocol wrote, adding that rsETH “remains fully backed” and that minting and withdrawals were unaffected.

That leaves the money in limbo. Whether Yoink returns it has a recent precedent: in January, an MEV builder that captured funds from a Makina exploit gave back about 920 of 1,023 ether, keeping a 10% bounty under the SEAL Whitehat Safe Harbor. Kelp’s restaking token was itself the subject of a $292 million bridge exploit in April, and the pattern of losses flowing through trusted infrastructure rather than core code has repeated across DeFi, most recently when Moonwell lost $8.7 million in August.

Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/a-bot-robbed-the-hacker-who-drained-7-8-million-in-rseth-from-a-safe-wallet\/#arve-youtube-cd-_g0jvf_e","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/cD-_G0Jvf_E?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}

The post A Bot Robbed the Hacker Who Drained $7.8 Million in rsETH From a Safe Wallet appeared first on Unchained.

Why this matters

Ethereum is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.

Original source

Read on Unchained

Related market context