A wallet on Ethereum that utilized leverage of rsETH was attacked on September 15, resulting in a loss of approximately 7.8 million US dollars. On-chain security firm Blockaid stated that the issue did not lie with the core rsETH contract of Kelp DAO, but rather with a custom Safe module that was integrated into that wallet.
The vulnerability lies in the custom module.
The affected wallet address is 0x40E93…7AbA8, which held approximately $7.73 million before the incident. Blockaid stated that there was a public interface for this Safe module, which is used for Uniswap and v4 liquidity pool operations. External callers could pass in custom data and execute code within the wallet context through DELEGATECALL.
Since this module has previously obtained authorization with the code Safe, attackers do not need to bypass the wallet's own permissions in order to control the wallet's assets through it.
The attack path points to a malicious pool.
According to the disclosed on-chain analysis, the attacker first utilized the public keeper and multicall functions to redirect these custom Uniswap, v4, Safe modules to a malicious Hook pool. Subsequently, the modules unpacked the aEthrsETH from the wallet into its original rsETH form and attempted to transfer assets out through this malicious pool.
However, the party that initially launched the attack did not ultimately obtain this funds. After the transaction entered the Ethereum memory pool, it was identified and intercepted by a bot named “yoink”, which then seized approximately 7.8 million US dollars.
Kelp Transfer suspension for 24 hours
Kelp DAO indicates that the core smart contract remains secure, and rsETH the fund pool is still in a fully collateralized state. The project team has temporarily suspended rsETH transfers for 24 hours to isolate the affected assets.
Kelp also states that the normal minting, redemption of rsETH, as well as other DeFi integrations, are still in operation. The article mentions that since rsETH is a type of liquid collateral re-pledge token, a wallet loss does not mean that the project team can directly retrieve an equal amount of tokens.
Additional information:If the relevant assets remain at the address controlled by “yoink”, subsequent handling will depend on whether the token design supports freezing, restrictions, or other recovery measures.












