Particle.news

MEV Bot Front‑Runs Gnosis Safe Exploit to Capture $7.8M in rsETH

Security firms say the event reveals a Safe-module authorization failure that let a malicious Uniswap v4 hook produce rsETH which an MEV bot then captured.

Overview

  • Security firms reported Tuesday that an attempted theft targeted about 2,900 rsETH worth roughly $7.8 million from a Gnosis Safe‑configured wallet and that the output was captured by an MEV bot called Yoink.
  • Researchers say the attacker used a public keeper multicall to route a custom Uniswap v4 Safe module into an attacker‑controlled hook pool that unwrapped aEthrsETH into rsETH for extraction.
  • BlockSec and others traced the root cause to a flawed authorization check in an executor contract tied to an enabled Safe module that let attacker‑controlled calls reach trusted execution paths.
  • On‑chain records show Yoink front‑ran the exploit in block 25980525, received about 2,900 rsETH, sent 2,882.37 rsETH to address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0 and routed the remainder through Uniswap v4 while the original exploit transaction reverted.
  • KelpDAO paused the receiving address for 24 hours and said rsETH is fully collateralised, but attribution, fund recovery and any legal action remain unresolved and the case highlights rising DeFi losses and risks from composable contract setups.