Tools Crypto Exploit Tracker exploit-0135
Exploit record
MEV bot captures 2,900 rsETH drained through a Safe module flaw
- Loss
- $7.7M
- Attack vector
- Access Control
- Chain
- Ethereum
- Sector
- Wallet
What happened
On 15 September 2026, an attacker used a public keeper multicall to drive a custom Uniswap v4 LP module on one user's Safe into an attacker-created hooked pool, which unwrapped the Safe's 2,900 rsETH. The MEV bot Yoink captured the unwrapped coins in flight, and 2,882.3674 rsETH settled at an address Kelp DAO paused for 24 hours. Blockaid confirms a $7.73m rsETH loss.
The flaw sat in the custom third-party module attached to the one Safe, with an entry point any caller could reach. The drain transaction confirmed at 04:38:47 UTC and carries an $8.13m on-chain valuation at the transaction-time rsETH price; Blockaid’s $7.73m stands as the confirmed loss figure. This is a separate event from the April 2026 Kelp DAO LayerZero bridge incident already in this log.
On-chain references
- Drain transactionetherscan.io/tx/0x0e7680b06cb8a6f86c149d9ba90d98e3d334e7b072…
- Paused receiving addressetherscan.io/address/0xC70f00CD7E461686b04B0E912E309becA8b80…
Sources
- Blockaid detectionx.com/blockaid_/status/2099732957803999342
- Kelp DAO pause noticex.com/KelpDAO/status/2099740756865159562
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 27 September 2026