Exploit Drains $7.8M In rsETH From User’s Safe Wallet Through Compromised Strategy Executor

Blockchain safety corporations Blockaid, PeckShield, and BlockSec have confirmed an exploit that drained roughly $7.8 million value of rsETH, round 2,900 tokens, from a Gnosis Safe pockets on Ethereum. The incident started at 04:38 UTC with a transaction that moved the majority of the funds, adopted by a number of smaller transactions over the subsequent hour totaling a further ~$160,000, in response to the corporations’ reviews.
The root trigger was a flawed authorization verify within the executor contract, recognized by analysts as deal with 0x4f0055926c839D1d960a82CBF84E2eE933958ebC.
The focused Safe, belonging to a big holder of leveraged rsETH, relied on a whitelisted technique executor module that uncovered a recipe entrypoint. This entrypoint forwarded absolutely caller-supplied calldata into the Safe’s execTransactionFromModuleReturnData perform utilizing operation=1 (DELEGATECALL) with out gating the exterior caller. Setting the equipped contract parameter to the executor’s personal deal with handed validation, that means anybody who may attain the entrypoint may execute arbitrary code throughout the Safe’s personal context — successfully gaining full management over its belongings.
The attacker used a public keeper multicall to route the approved Uni V4 LP Safe module into an attacker-created hooked Uniswap V4 pool, executing by way of Permit2 and the PositionManager. The attacker had deployed a nugatory token dubbed the “Permissionless Attacker Token” (PAT) and equipped roughly 2,900 aEthrsETH as liquidity in opposition to it. A customized hook within the pool unwrapped the aEthrsETH into rsETH and siphoned it out of the Safe, which was left holding a worthless LP NFT.
MEV Bot Front-Runs Attack; KelpDAO Imposes Temporary Pause
Notably, the unique assault transaction by no means reached its meant beneficiary. The attacker launched the exploit straight into the general public mempool, the place it was front-run by an MEV bot named “yoink,” which captured your entire ~2,882 rsETH — value roughly $7.8 million — and routed it to handle 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. In impact, a maximal extractable worth bot, not the attacker, walked away with the stolen funds.
In response, KelpDAO introduced it had detected suspicious exercise on the receiving deal with and positioned it below a precautionary 24-hour pause, throughout which rsETH can’t transfer in or out. The crew acknowledged it’s working with safety specialists on the investigation, and emphasised that the measure is wallet-level solely: Kelp contracts stay protected, rsETH stays absolutely backed, and all minting, withdrawal, and integration operations proceed usually, with no motion required from customers.
Security analysts careworn that this was module-authorization abuse particular to 1 Safe, not a vulnerability in Safe’s core contracts or proprietor keys. The incident nonetheless highlights a persistent threat for sensible contract pockets customers: Safe’s core has by no means suffered a direct protocol exploit, however customers have repeatedly misplaced funds via compromised infrastructure and susceptible third-party extensions, together with over $2 million stolen in address-poisoning assaults affecting 21 Safe customers in 2023.
The put up Exploit Drains $7.8M In rsETH From User’s Safe Wallet Through Compromised Strategy Executor appeared first on Metaverse Post.

Blockaid exploit detection system detected an exploit on an unidentified consumer’s Safe on Ethereum.