Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Currencies39185
Market Cap$ 2.72T-0.94%
24h Spot Volume$ 37.58B-2.37%
DominanceBTC56.83%-0.20%ETH11.12%-0.42%
ETH Gas0.06 Gwei
News
Sep 15, 2026
2min read
byRizwan Ansari
forCoinpedia

On September 15, 2026 Blockaid traced an exploit that compromised a Gnosis Safe holding about $7.73M of rsETH via a custom Uniswap v4 LP Safe module whose public DELEGATECALL entrypoint allowed an attacker to unpack aEthrsETH into rsETH and execute code inside the wallet. The attacker’s extraction was then front-run in the mempool by MEV bot “yoink,” which captured roughly $7.8M; Kelp DAO paused rsETH transfers for 24 hours, said core rsETH contracts and the pool remain collateralized, and warned recovery depends on token controls, highlighting a material DeFi security risk.
See what traders are focused on
An Ethereum wallet holding leveraged rsETH has lost around $7.8 million after an attacker exploited a custom Safe module linked to a Uniswap v4 liquidity pool. The incident happened on September 15, 2026, but security researchers said the attack did not come from a flaw in Kelp DAO’s core rsETH contracts.
Here’s how the exploit actually happen.
Custom Safe Module Exposed Wallet to Attack
Blockchain security firm Blockaid identified the attack and traced it to a custom Uniswap v4 LP Safe module used by the affected Gnosis Safe wallet.
The wallet at 0x40E93…7AbA8 held about $7.73 million worth of rsETH before the attack.
According to the security analysis, the module had a public entry point that accepted caller-controlled data and used DELEGATECALL without proper access checks.
Because the module was already authorized by the Safe, an outside attacker could use that entrypoint to execute code inside the wallet’s own context.
This gave the attacker control over the wallet’s assets.
How rsETH Exploit Happen?
The attacker first used a public keeper multicall function to redirect the wallet’s custom Uniswap v4 Safe module toward a malicious Hook pool.
The module then unpacked the wallet’s aEthrsETH, an Aave-wrapped version of restaked ETH, into raw rsETH. The attacker attempted to extract those tokens through the malicious pool.
Perhaps, the original attacker did not get the stolen funds.
Because the attacker’s transaction entered Ethereum’s mempool, where an MEV bot known as “yoink” detected and front-ran the transaction and captured the entire roughly $7.8 million worth of rsETH for itself.
Can Kelp just withdraw the $7.8M from rsETH?
Not necessarily. As rsETH is a liquid restaking token. The fact that the wallet held $7.8M worth of rsETH does not mean Kelp DAO has a $7.8M pile of the same tokens that it can simply take back.
If the stolen rsETH remains in an address controlled by Yoink, recovery would generally require freezing, blacklisting, recovering, or otherwise restricting those assets, if the token’s design and applicable controls allow it.
Kelp DAO Says Core rsETH Contracts Are Safe
Meanwhile Kelp DAO team has responded by temporarily pausing rsETH transfers for 24 hours to isolate the affected funds.
The team said its core smart contracts remained secure and that the rsETH pool was fully collateralized. Normal minting, redemptions, and other DeFi integrations continued to operate.
Source: cryptorank.io