W3BStation
Markets
BTC $96,420 +2.34% ETH $3,280 +1.82% SOL $185.40 -0.92% BNB $642.50 +0.45% XRP $2.18 +3.12% DOGE $0.082 -1.50% ADA $1.05 +0.80% AVAX $42.10 +1.15%
BTC $96,420 +2.34% ETH $3,280 +1.82% SOL $185.40 -0.92% BNB $642.50 +0.45% XRP $2.18 +3.12% DOGE $0.082 -1.50% ADA $1.05 +0.80% AVAX $42.10 +1.15%
09/15/2026

Coding Flaw in Safe Wallet Helper Lets MEV Bot Seize $7.8M in rsETH

What happened: On September 15, 2026, a Gnosis Safe multisig wallet on Ethereum lost approximately 2,882 rsETH (worth $7.

Coding Flaw in Safe Wallet Helper Lets MEV Bot Seize $7.8M in rsETH

What happened: On September 15, 2026, a Gnosis Safe multisig wallet on Ethereum lost approximately 2,882 rsETH (worth $7.8 million) after a helper contract with a faulty authorization check was exploited. The attacker used a whitelisted Multicall/Strategy Executor module to route funds through a custom Uniswap V4 pool, but a MEV bot named "yoink" front-ran the exploit, paying about $47,000 in gas fees to capture the funds. The victim wallet address and transaction hash have not been publicly disclosed. KelpDAO responded by pausing rsETH transfers to the receiving address for 24 hours as a precaution.

Why it matters: This incident underscores the risks of module-level vulnerabilities in wallet infrastructure, even when core contracts remain secure. The exploit was not due to a flaw in Safe or KelpDAO's main contracts but stemmed from a misconfigured helper module, highlighting the importance of rigorous security reviews for all authorized modules. Notably, the original attacker did not profit; the MEV bot ultimately seized the funds, demonstrating the unpredictable dynamics of on-chain exploits.

Source: CoinDesk, PANews, Metaverse Post, Messari