First, let’s say: it’s not that Safe itself isn’t secure—the custom module attached to the wallet left the backdoor too wide open.

At about 04:38 UTC on September 15, security firms including Blockaid traced an incident involving an Ethereum Safe where there was abuse of module authorization. The attacker used a public keeper multicall to route a custom Uniswap v4 liquidity module into an attacker-controlled hooked pool, splitting aEthrsETH into roughly 2,900 $rsETH valued at about $7.73 million (the media also reported a figure around $7.8 million). The security assessment classified it as module-authorization abuse, not a compromise of the Safe core or the owner key.

What’s more dramatic is the same block: the MEV searcher Yoink front-ran and packaged transactions in the public mempool, paying the builder about 18.93 $ETH (about $46k), taking away around 2882 $rsETH. After the hacker finished the job, the money first landed in the robot’s pocket.

Kelp ($rsETH protocol) then put the receiving address on a 24-hour wallet-level pause and stated: the Kelp contract is operating normally, and $rsETH is still fully backed—minting/redemption/integration are not paused. The risk lies in user-customized modules, not in the protocol’s main contract. Whether the money ultimately returns to users depends on follow-up white-hat negotiations; in past cases, someone kept about 10% bounty before refunding the rest.

My filter: multi-sig modules = an expanded permission surface. The “convenience” of being able to co-sign is an entry point that others can also use to spend. On-chain, in the publicly visible mempool, front-running can be faster than the hacker sometimes.

This does not constitute investment advice.

#ETH #rsETH #MEV #安全 #day by day, one step at a time