$7.8M rsETH stolen from Ethereum Safe via Uniswap v4 exploit

A Gnosis Safe wallet lost $7.8M in rsETH after a custom module exploit routed funds through a malicious Uniswap v4 pool. An MEV bot front-ran the attack. Kelp DAO paused the wallet.

On September 15, 2026, an Ethereum Gnosis Safe wallet lost approximately $7.8 million in rsETH after an attacker exploited a custom module. The attacker routed assets through a malicious Uniswap v4 liquidity pool they controlled. This exploit was possible due to a flawed authorization check in a strategy executor contract, which allowed arbitrary code execution within the Safe’s context. The attacker used a public keeper multicall to invoke a custom Uniswap v4 LP Safe module, directing liquidity into a hooked pool. This process converted aEthrsETH—representing rsETH supplied to Aave—into transferable rsETH, which was then extracted. A Maximal Extractable Value (MEV) bot named Yoink front-ran the exploit and captured most of the tokens. Kelp DAO, the issuer of rsETH, responded by pausing the receiving wallet for 24 hours and confirmed that core contracts and rsETH backing remained unaffected. The incident did not compromise Safe’s core multisig contracts or Ethereum itself, but it highlights the risks associated with custom modules and hooks in DeFi protocols.