Back Tradingview Ethereum Wallet Loses $7.8 Million in rsETH Exploit
An Ethereum wallet holding leveraged rsETH has lost around $7.8 million after an attacker exploited a custom Safe module linked to a Uniswap v4 liquidity pool. The incident happened on September 15, 2026, but security researchers said the attack did not come from a flaw in Kelp DAO’s core rsETH contracts.
Here’s how the exploit actually happen.
Custom Safe Module Exposed Wallet to Attack
Blockchain security firm Blockaid identified the attack and traced it to a custom Uniswap v4 LP Safe module used by the affected Gnosis Safe wallet.
The wallet at 0x40E93…7AbA8 held $7.73 million worth of rsETH before the attack.
Blockaid @blockaid_ 🚨Blockaid exploit detection system detected an exploit on an unidentified user's Safe on Ethereum. ~$7.73M confirmed rsETH loss so far. An attacker used a public keeper multicall to drive a custom Uni V4 LP Safe module into an attacker-created hooked pool; the hook unwrapped…
🚨Blockaid exploit detection system detected an exploit on an unidentified user's Safe on Ethereum.
~$7.73M confirmed rsETH loss so far.
An attacker used a public keeper multicall to drive a custom Uni V4 LP Safe module into an attacker-created hooked pool; the hook unwrapped…
According to the security analysis, the module had a public entry point that accepted caller-controlled data and used DELEGATECALL without proper access checks.
Because the module was already authorized by the Safe, an outside attacker could use that entrypoint to execute code inside the wallet’s own context.
This gave the attacker control over the wallet’s assets.
How rsETH Exploit Happen?
The attacker first used a public keeper multicall function to redirect the wallet’s custom Uniswap v4 Safe module toward a malicious Hook pool.
The module then unpacked the wallet’s aEthrsETH, an Aave-wrapped version of restaked ETH, into raw rsETH. The attacker attempted to extract those tokens through the malicious pool.
Perhaps, the original attacker did not get the stolen funds.
Because the attacker’s transaction entered Ethereum’s mempool, where an MEV bot known as “yoink” detected and front-ran the transaction and captured the entire roughly $7.8 million worth of rsETH for itself.
Can Kelp just withdraw the $7.8M from rsETH?
Not necessarily. As rsETH is a liquid restaking token. The fact that the wallet held $7.8M worth of rsETH does not mean Kelp DAO has a $7.8M pile of the same tokens that it can simply take back.
If the stolen rsETH remains in an address controlled by Yoink, recovery would generally require freezing, blacklisting, recovering, or otherwise restricting those assets, if the token’s design and applicable controls allow it.
Kelp DAO Says Core rsETH Contracts Are Safe
Meanwhile Kelp DAO team has responded by temporarily pausing rsETH transfers for 24 hours to isolate the affected funds.
Kelp @KelpDAO We've detected potential suspicious activity on an the address (0xc70f00cd7e461686b04b0e912e309beca8b80ea0) that received rsETH a few hours ago. Out of an abundance of caution, we've placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in…
We've detected potential suspicious activity on an the address (0xc70f00cd7e461686b04b0e912e309beca8b80ea0) that received rsETH a few hours ago.
Out of an abundance of caution, we've placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in…
The team said its core smart contracts remained secure and that the rsETH pool was fully collateralized. Normal minting, redemptions, and other DeFi integrations continued to operate.
More news from Coinpedia
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
