🚨 $7.73M DRAINED FROM GNOSIS SAFE 🚨

Another day, another multi-million exploit. SlowMist caught this one:

The Attack:
Router contract (0x4f005592…) had a fatal flaw in `multicall(address, bytes[])`. Attacker set `_contract` to `address(this)`, making `_isAuthorized` return true unconditionally. Game over.

Victim's Safe module got hijacked via DelegateCall → attacker injected aEthrsETH into a malicious liquidity pool with a custom hook → swapped out → profit.

Addresses:
🔴 Attacker: 0x2f7e143e27f2fa26ef3b8ac72698f1d321422f67
🔴 Victim: 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
🔴 Vulnerable Contract: 0x4f0055926c839d1d960a82cbf84e2ee933958ebc

If you're using this Router or similar multicall logic, audit NOW. DelegateCall + weak auth checks = exit liquidity for hackers.

Stay safe out there.