An Ethereum Gnosis Safe wallet lost ~$7.73M (~2,900 rsETH) after an attacker used a public keeper multicall to route the wallet's custom Uniswap v4 liquidity module into an attacker-controlled hooked pool. An MEV bot named 'Yoink' front-ran the attacker and captured the rsETH; Kelp DAO placed the receiving address under a 24-hour pause.
On September 15, 2026, an Ethereum Gnosis Safe wallet lost ~$7.73M (~2,900 rsETH). An attacker used a public keeper multicall to route the wallet's custom Uniswap v4 liquidity module into an attacker-controlled hooked pool, converting aEthrsETH into transferable rsETH. The failure path was the account's custom module and the malicious hook, not Safe's core contracts. An MEV bot named 'Yoink' front-ran the attacker and captured the rsETH within the same block, transferring ~18.93 ETH (~$46K) to a block builder. Kelp DAO placed the receiving address under a 24-hour pause and confirmed its contracts were safe and rsETH fully backed. Blockaid reported the incident.
The MEV bot 'Yoink' front-ran the attacker and captured the rsETH within the same block, transferring ~18.93 ETH (~$46K) to a block builder. Kelp DAO placed the receiving address under a 24-hour pause.