Just imagine you blink eye and loss $7.8M, Yes it is not a joke it happened today

$7.8M was stored in a multi signature wallet

The Safe itself wasn’t hacked

The owner keys weren’t cracked

Kelp wasn’t insolvent

So how did the money disappear?

A user had enabled an automation/module stack that could move funds without requiring a fresh multisig signature every time. One of those components exposed a dangerous authorization path.

An attacker found it.

In roughly 24 seconds, they deployed a worthless token, created a Uniswap v4 pool against rsETH collateral, and prepared the extraction.

Then the memepool comes into the scene

A searcher called “Yoink” copied the profitable transaction, got it into block #1, and captured roughly 2,900 rsETH worth about $7.8M before the original exploit could suceceed

That creates an even stranger situation

The attacker lost the money they were trying to steal

But the searcher that front-ran the exploit got the assets instead

And no, that doesn’t automatically make Yoink a whitehat. The funds were not returned to the victim, and Yoink later liquidated additional collateral from the same position

The bigger lesson for crypto users is much more uncomfortable:

A multisig can have strong owner security while still carrying dangerous permissions that the owner grant.

Every module, router, keeper and automation contract expands the attack surface.

The blockchain may be working exactly as designed.

Your permission model can still be broken.

That’s the part people usually notice only after millions are gone.

#btc #ETH #FedRateWatch #doge #bnb $BTC $ETH $BNB