A Bot Robbed the Hacker Who Drained $7.8 Million in rsETH From a Safe Wallet
An attacker drained about $7.8 million in rsETH from an Ethereum Safe wallet early Tuesday, then lost the payout to a bot that was watching the same block. The theft, first flagged by security firm Blockaid, moved roughl...
Watchlist
Published in the last two hours. Multiple named entities are involved.
An attacker drained about $7.8 million in rsETH from an Ethereum Safe wallet early Tuesday, then lost the payout to a bot that was watching the same block. The theft, first flagged by security firm Blockaid, moved roughly 2,900 rsETH out of a Gnosis Safe at 04:38 UTC. In the same block, a generalized MEV searcher known as Yoink front-ran the attacker’s own transaction, paying about $46,000 to the block’s builder to have its transaction ordered first, and walked away with the funds instead.
The wallet itself was never the weak point. Blockaid described the incident as “module-authorization abuse on that Safe, not a Safe core / owner-key bug,” and researchers at BlockSec, SlowMist and AstraSec traced the fault to the same spot: a Multicall helper the wallet’s owner had approved. The helper treated any call that pointed back at its own address as pre-authorized, so an outsider could push instructions through the module and have the Safe run them as if they were its own.
The Module Was the BackdoorSafe multisigs let owners bolt on third-party modules that can move funds without collecting the usual signatures. Here, a custom Uniswap v4 liquidity module exposed an entrypoint that forwarded attacker-supplied instructions into the wallet. The attacker pointed it at a pool he controlled, unwrapped the wallet’s yield-bearing aEthrsETH into ordinary rsETH, and left behind worthless receipts. Safe’s own contracts did exactly what an authorized module told them to.
A Bot Beat the Attacker to ItBecause the exploit transaction sat in the public mempool, Yoink saw it coming and executed first in the same block, capturing 2,882 rsETH and routing it to a fresh address. Restaking protocol Kelp DAO froze that address within two hours. “Out of an abundance of caution, we’ve placed that address under a temporary 24-hour pause,” the protocol wrote, adding that rsETH “remains fully backed” and that minting and withdrawals were unaffected.
That leaves the money in limbo. Whether Yoink returns it has a recent precedent: in January, an MEV builder that captured funds from a Makina exploit gave back about 920 of 1,023 ether, keeping a 10% bounty under the SEAL Whitehat Safe Harbor. Kelp’s restaking token was itself the subject of a $292 million bridge exploit in April, and the pattern of losses flowing through trusted infrastructure rather than core code has repeated across DeFi, most recently when Moonwell lost $8.7 million in August.
Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money
{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/a-bot-robbed-the-hacker-who-drained-7-8-million-in-rseth-from-a-safe-wallet\/#arve-youtube-cd-_g0jvf_e","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/cD-_G0Jvf_E?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}
The post A Bot Robbed the Hacker Who Drained $7.8 Million in rsETH From a Safe Wallet appeared first on Unchained.
Why this matters
Ethereum is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on UnchainedRelated market context
MEV Bot Front-Runs $7.8 Million rsETH Exploit on Ethereum
An MEV bot known as Yoink front-ran an exploit targeting a Safe wallet on Ethereum on Tuesday. PeckShield described the incident a...
DeFi governance gap allows one wallet to request 98% of Ampleforth treasury’s USDC balance
Ampleforth, a DeFi protocol governed by FORTH token holders, saw Proposal 54 canceled on-chain before its voting window opened. Th...
DeFi stalwart Balancer mulls shutdown after $130M hack
Once a household name in the DeFi sector, decentralized exchange Balancer is considering calling it quits. In a proposal posted to...
Ethereum and Base Abandon a Shared Wallet Standard as Account-Abstraction Talks Break Down
Ethereum and Base have given up on building one shared account-abstraction standard for both networks and will ship competing desi...
ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address
An MEV bot known as “Yoink” front-ran an attacker attempting to exploit a custom Safe module, capturing the stolen rsETH before Ke...
How a simple coding mistake let a hacker drain $7.8 million from a crypto wallet
Security firms traced the $7.8 million loss to a helper contract the wallet owner had authorized, not to Safe itself.