An attacker tried to exploit an authorization flaw in a Multicall contract approved by a Safe multisig wallet to move about 2,900 rsETH. According to ChainCatcher, the automated trading bot yoink spotted the transaction in the public mempool, paid about $47,000 in fees to front-run it, and intercepted 2,882 rsETH before sending them to another address.

BlockSec, Blockaid, SlowMist, and AstraSec said the issue was in a user-authorized component rather than Safe's core contract. rsETH issuer Kelp DAO has placed a 24-hour pause on the receiving address.