A flawed authorization check exposed an Ethereum Safe wallet holding roughly 2,900 rsETH, worth $7.73M. MEV bot Yoink front-ran the attacker’s drain and extracted the assets in the same block.
- The exploit abused a public Multicall keeper call and a custom Uniswap v4 LP Safe module.
- A malicious hooked pool unwrapped aEthrsETH into rsETH, enabling the attempted withdrawal.
- The vulnerability was in the wallet’s added Multicall component—not Safe’s core contracts; Kelp restricted the recipient for 24 hours.
This is a brutal reminder: delegated modules are the real attack surface around multisigs. Treat “trusted” automation as hot-wallet infrastructure, revoke unnecessary permissions, and monitor module calls in real time.



