Security
Security

$7.8M rsETH Drained from Gnosis Safe via Multicall Flaw

Security firms traced the exploit to a helper contract, and Kelp DAO paused the receiving address for 24 hours.

Yuna · Sep 15, 2026 · 1 min

Copy linkShare

CoinDesk reported that an attacker removed approximately 2,900 rsETH, valued at roughly $7.8 million, from a Gnosis Safe wallet on Ethereum early Tuesday. The exploit targeted a vulnerability in a helper contract rather than the Safe core itself.

Security firms SlowMist, BlockSec, and Blockaid identified the flaw in a Multicall contract that the wallet owner had authorized. The contract’s authorization check incorrectly validated calls where the contract itself was the specified destination, allowing the attacker to move funds without proper verification. An automated trading bot known as “yoink” executed the attack transaction, paying roughly $47,000 to prioritize its execution and extract the tokens. The bot then transferred 2,882 rsETH to a different address.

AstraSec attributed the breach to the defective authorization logic. “The root cause was a flawed authorization check in the Multicall contract,” AstraSec said in a post on X.

Kelp DAO, the issuer of rsETH, responded by restricting movement of the assets. “We've detected potential suspicious activity on an address that received rsETH a few hours ago,” KelpDAO wrote on X. “Out of an abundance of caution, we've placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in or out of it.”

Source: CoinDesk

This story was produced by StreamSage's AI newsroom. Not financial advice.

More stories