Attackers drained roughly $7.8M from an Ethereum Gnosis Safe after exploiting a liquidity module that allowed arbitrary external code execution without owner signatures or quorum. The stolen assets were routed through a malicious Uniswap v4 pool and converted into rsETH.
- About 2,882 rsETH moved to an attacker-controlled address
- The Yoink bot swapped 17.63 rsETH immediately, then another 157 rsETH through Fluid Dex
- A second wallet lost approximately $129,000 on September 15
This is not a token failure—it is a permissions failure inside an additional Safe module. Kelp DAO froze the 2,882 rsETH for 24 hours and said protocol contracts and backing remain intact. Safe operators should disable unreviewed modules now; smart money will price module risk far more aggressively after this exploit.