خبری درباره‌ی Safe (SAFE)

MEV Bot Captures $7.7M in rsETH After Safe Module Exploit

Finance Feeds ۹ دقیقه پیش خلاصه‌ی فارسی · ۴۶۰ کلمه
MEV Bot Captures $7.7M in rsETH After Safe Module Exploit

How Did the Attacker Target the Safe Wallet? An attacker attempting to extract roughly $7.7 million in rsETH from an Ethereum Safe wallet was front-run by an MEV bot, leaving most of the funds temporarily trapped at an address that Kelp DAO subsequently restricted. Blockchain security firm Blockaid traced the incident to a custom module connected to the unidentified user's Safe rather than to a vulnerability in Safe's core wallet contracts or Kelp's rsETH protocol. The attacker used a publicly accessible keeper multicall to route a custom Uniswap v4 liquidity module through an attacker-created pool containing a malicious hook. That hook allowed aEthrsETH held through the wallet's leveraged position to be unwrapped into transferable rsETH. Approximately 2,900 rsETH was extracted from the position, with Blockaid initially valuing the affected assets at about $7.73 million. The module was already authorized to execute transactions through the Safe, making its permissions particularly important. The attack path effectively used that trusted module to move assets without obtaining the wallet owners' normal signatures. That distinction matters because the incident does not appear to represent a compromise of Safe's underlying multisignature architecture. Instead, it shows how adding third-party modules can expand the execution permissions — and attack surface — of a smart-contract wallet. Why Did the Original Exploiter Lose the Funds? The attack did not unfold as intended. The transaction was detected by an MEV bot known as Yoink, which front-ran the original exploiter and captured the rsETH within the same Ethereum block. MEV searchers monitor pending blockchain transactions and attempt to reorder or insert their own transactions when profitable opportunities appear. In this case, Yoink reproduced the extraction before the original attacker could complete it. On-chain data shows the bot moved roughly 2,882 rsETH, representing the overwhelming majority of the main extraction, to a separate address. Part of the transaction's value was also converted, while approximately 18.93 ETH, worth about $46,000 at the time, was transferred to an address identified as a block builder. The intervention therefore prevented the original exploiter from taking direct control of most of the rsETH, but it does not by itself mean the victim has recovered the assets. Control instead shifted to another on-chain actor whose intentions have not been publicly established. Investor Takeaway The incident is primarily a wallet-module security failure rather than an rsETH protocol exploit. For DeFi users, the larger risk is that an authorized automation or strategy module can inherit powerful wallet permissions even when the underlying multisig and token contracts remain secure. Can Kelp Prevent the rsETH From Moving? Kelp responded by placing the address holding most of the intercepted rsETH under a temporary 24-hour pause, preventing those tokens from moving while the incident is investigated. “This is a precautionary, wallet-level measure only,” Kelp said.

عنوان اصلی (انگلیسی): MEV Bot Captures $7.7M in rsETH After Safe Module Exploit

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Safe

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.