FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.6T -1.5%24h Vol $12112304.1T +13297434235%Fear & Greed 69/100Alts Index 29/100
BTC.D 58.3% -0.3%Stable.D 10.0% +0.1%ETH.D 11.2% -0.3%Others.D 20.5% +0.5%
AKE$0.0273+78.56%AI$0.3214+35.32%龙虾$0.1779+19.42%ARC$0.0812+13.87%牛来$0.1189+11.99%FF$0.1407+10.66%LAPTOP$0.2390+9.71%CAP$0.0603+2.49%NFT$0.00000024+2.4%JST$0.1147+1.51%
UAI$0.3767-28.04%LSK$0.3404-19.78%SENT$0.0143-17.7%B$0.1990-17.24%FIL$0.8191-15.07%INJ$5.478-14.31%RAY$1.210-13.44%SPX$0.4564-12.19%AR$2.477-12.15%RAIN$0.0132-12.14%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      MEV Bot Captures $7.7M in rsETH After Safe Module Exploit

      How Did the Attacker Target the Safe Wallet?

      An attacker attempting to extract roughly $7.7 million in rsETH from an Ethereum Safe wallet was front-run by an MEV bot, leaving most of the funds temporarily trapped at an address that Kelp DAO subsequently restricted.Blockchain security firm Blockaid traced the incident to a custom module connected to the unidentified user's Safe rather than to a vulnerability in Safe's core wallet contracts or Kelp's rsETH protocol.The attacker used a publicly accessible keeper multicall to route a custom Uniswap v4 liquidity module through an attacker-created pool containing a malicious hook. That hook allowed aEthrsETH held through the wallet's leveraged position to be unwrapped into transferable rsETH.Approximately 2,900 rsETH was extracted from the position, with Blockaid initially valuing the affected assets at about $7.73 million.The module was already authorized to execute transactions through the Safe, making its permissions particularly important. The attack path effectively used that trusted module to move assets without obtaining the wallet owners' normal signatures.That distinction matters because the incident does not appear to represent a compromise of Safe's underlying multisignature architecture. Instead, it shows how adding third-party modules can expand the execution permissions — and attack surface — of a smart-contract wallet.

      Why Did the Original Exploiter Lose the Funds?

      The attack did not unfold as intended. The transaction was detected by an MEV bot known as Yoink, which front-ran the original exploiter and captured the rsETH within the same Ethereum block.MEV searchers monitor pending blockchain transactions and attempt to reorder or insert their own transactions when profitable opportunities appear. In this case, Yoink reproduced the extraction before the original attacker could complete it.On-chain data shows the bot moved roughly 2,882 rsETH, representing the overwhelming majority of the main extraction, to a separate address. Part of the transaction's value was also converted, while approximately 18.93 ETH, worth about $46,000 at the time, was transferred to an address identified as a block builder.The intervention therefore prevented the original exploiter from taking direct control of most of the rsETH, but it does not by itself mean the victim has recovered the assets. Control instead shifted to another on-chain actor whose intentions have not been publicly established.

      Investor Takeaway

      The incident is primarily a wallet-module security failure rather than an rsETH protocol exploit. For DeFi users, the larger risk is that an authorized automation or strategy module can inherit powerful wallet permissions even when the underlying multisig and token contracts remain secure.

      Can Kelp Prevent the rsETH From Moving?

      Kelp responded by placing the address holding most of the intercepted rsETH under a temporary 24-hour pause, preventing those tokens from moving while the incident is investigated.“This is a precautionary, wallet-level measure only,” Kelp said. “Kelp contracts are safe, rsETH remains fully backed.”The protocol said minting, withdrawals and integrations were continuing normally and that no broader action was required from rsETH users.The pause creates a limited containment window around the largest block of assets. On-chain tracking indicates approximately 2,882 rsETH from the primary transaction remained at the restricted receiving address after the MEV extraction. Some value involved in related transactions had already been routed elsewhere, meaning the wallet-level restriction does not necessarily cover every asset associated with the incident.The next question is whether the MEV operator cooperates with efforts to return the captured tokens, and what happens when Kelp's temporary restriction expires.

      What Does the Exploit Mean for Smart Wallet Security?

      The attack illustrates a growing security problem around programmable wallets. Safe accounts can extend their functionality through modules that automate trading, liquidity management and other DeFi strategies, but those extensions may receive authority that bypasses normal owner-by-owner transaction approval.That means the security of a multisignature wallet can depend on more than its private keys and signing threshold. A poorly protected module with permission to execute transactions can become an alternative route into the wallet.For protocols and institutional users running automated DeFi strategies, reviewing callable functions, access controls and delegated execution rights may therefore be as important as protecting signer keys.The immediate rsETH exposure appears contained largely at the wallet level, while Kelp says its token remains fully backed. The unresolved issue is whether the roughly $7.7 million intercepted by Yoink can ultimately be returned to the affected Safe before the temporary restrictions are lifted.

      Source: FinanceFeeds
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud