
An attacker successfully exploited a Gnosis Safe wallet on Ethereum, removing approximately 2,900 rsETH worth roughly $7.8 million on Tuesday. According to reports from security firms BlockSec, Blockaid and SlowMist, the theft was facilitated by an automated bot known as 'yoink' that front-ran the attack transaction and extracted the tokens. The victim's wallet was set up to allow a helper contract to move money on its behalf, a common arrangement for automated trading operations.
The attacker dumped the stolen rsETH into a trading pool built minutes earlier around a worthless token called Permissionless Attacker Token, leaving the wallet with a receipt worth nothing. As reported by security firms, yoink's bot paid approximately $47,000 to jump the queue and took the tokens, sending 2,882.37 rsETH to address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, which held 2,882.36740883 rsETH at the time of review. The remaining 17.63 rsETH moved to the Uniswap v4 Pool Manager, which then sent 18.95 ETH to the Yoink contract, with 18.93 ETH forwarded to the block builder. Both Yoink's transaction and the original exploit attempt landed in block 25980525, with Yoink appearing at the top while the original transaction reverted.
The root cause was identified as a flawed authorization check in the Multicall contract, according to AstraSec. BlockSec attributed the underlying weakness to faulty authorization checks in an executor contract connected to an enabled Safe module, where attacker-controlled calls could pass through an executor that the wallet treated as trusted. Safe is a smart contract wallet system that can require several signers to approve transactions, with module framework allowing account owners to add contracts under predefined rules. Blockaid provided additional details showing the attacker accessed a public keeper multicall and directed a custom Uniswap v4 liquidity module toward a hook pool under their control, using unpacking instructions to convert aEthrsETH into rsETH. The failure was traced to a component the wallet owner had chosen to trust, not in Safe's core contracts.
Kelp DAO, which issues rsETH, responded by placing the address under a temporary 24-hour pause out of caution. As reported by KelpDAO, they detected potential suspicious activity on the address that received rsETH and implemented the restriction to prevent further movement of the stolen tokens. The company stated that its contracts are secure and rsETH is fully collateralized, indicating confidence in their overall security measures. The incident adds to significant DeFi losses in 2026, with protocols losing at least $1.3 billion to exploits during the first eight months according to CertiK and Forbes estimates. No U.S. regulator or law-enforcement agency has announced action involving Yoink or the attempted rsETH exploit based on the available information.