An attacker drained roughly 2,900 rsETH, valued at approximately $7.8 million, out of an Ethereum-based Gnosis Safe wallet early Tuesday.
Security companies BlockSec, Blockaid, and SlowMist noted that an automated trading bot named “yoink” front-ran the malicious transaction to capture the tokens.
The compromised wallet was configured to allow a helper contract to execute fund transfers, which is a standard setup for individuals utilizing trading automation. While the helper was designed to confirm that callers held proper authorization, BlockSec and SlowMist discovered that the validation loop accepted any caller designating the helper contract itself as the intended destination.
Subsequently, the hacker transferred about 2,900 rsETH into a liquidity pool established only minutes prior around a worthless asset named Permissionless Attacker Token, leaving the victim’s wallet holding a worthless return receipt. Yoink’s bot spent roughly $47,000 in priority fees to bypass the queue, seized the tokens, and routed 2,882 rsETH to a separate destination.
AstraSec stated in a post on X that the underlying issue stemmed from an invalid authorization check inside the Multicall contract. Additional security firms concurred that the vulnerability resided in an auxiliary element that the wallet holder trusted rather than the foundational Safe protocols. Meanwhile, Kelp DAO, the issuer of rsETH, maintained that its own infrastructure is secure and that rsETH remains fully backed.
KelpDAO stated on X that they identified potential abnormal behavior on an address that took in rsETH a few hours prior. To ensure safety, they implemented a temporary 24-hour restriction on that address, during which rsETH transfers in or out are frozen.
Originally published at https://www.coindesk.com/business/2026/09/15/how-a-simple-coding-mistake-let-a-hacker-drain-usd7-8-million-from-a-crypto-wallet.