以太坊 Safe 钱包因恶意模块与 Uniswap V4 Hook 损失约 773 万美元 rsETH
一名以太坊用户因攻击者利用 Safe 模块执行路径,将资产重定向至攻击者控制的 Uniswap v4 流动性池,导致约 773 万美元的 rsETH 资产损失。此次针对特定 Safe 地址的攻击发生于 9 月 15 日凌晨,安全监控识别出两笔引发资产流失的交易。现有证据表明,问题根源在于该钱包的自定义模块与恶意 Hook 之间的交互,而非 Safe 核心智能账户合约存在漏洞。
自定义模块将资产路由至恶意池
此次攻击利用了公共 Keeper 的多调用(multicall)机制,调用了绑定在该账户上的自定义 Uni V4 LP Safe 模块。执行过程将流动性引导至一个由攻击者控制 Hook 创建的 Uniswap v4 池中,从而使恶意路由逻辑能够访问该头寸涉及的资产。
随后,该 Hook 将受害者的 aEthrsETH 头寸转换为可转移的 rsETH。aEthrsETH 代表存入 Aave 的 rsETH,这意味着在提取底层 rsETH 之前,攻击者必须先将该头寸从其 Aave 收据代币形式中移出。
Safe 的模块架构允许授权扩展独立于常规多重签名流程执行交易。虽然模块可以自动化复杂的 DeFi 操作,但 Safe 警告称,这些模块具有极高的安全性风险,因为启用恶意或有漏洞的模块可能导致账户执行任意交易。
The attack did not promise Safe's core multi-signature contracts, signature keys or the Ethereum network itself. The identified failure paths involve custom modules for the account and Uniswap v4 Hook controlled by the attacker. A similar situation occurred in the previous SquidRouter module vulnerability in May, when the vulnerability cleared funds from 86 Safe accounts on the Ethereum and Base networks, but the underlying Safe contract was not affected.
MEV Robot Capture and Extraction Process
A MEV (Maximum Extractable Value) operation linked to an address marked by Etherscan as "MEV Frontrunner Yoink" intercepted the attack transaction within the block. The robot preached the original extraction transaction and captured a profitable transaction path before the attacker completed the commit. Although the change in transaction order caused the external address to eventually intercept most of the extracted value, the victim still lost rsETH because the underlying malicious execution was successful.
In the end, the Safe Wallet retained only liquidity positions NFT from the malicious pool, and no longer held previously held positions backed by rsETH.
rsETH refocuses on security issues
rsETH is a liquidity pledge token launched by Kelp DAO and is currently widely integrated in the Ethereum lending and liquidity markets. Its use in Aave led to the aEthrsETH collateral involved in this latest wallet theft incident. In April this year, Kelp DAO suffered a major security outage, releasing approximately $292 million in rsETH from cross-chain infrastructure and creating huge downstream exposure in the DeFi lending market.
The loss on September 15 was an independent incident. Current evidence focuses on the module execution of individual Safe, the attacker's controlled Uniswap v4 Hook, and the resulting rsETH position conversion supported by the wallet Aave. No broader compromise has been found for Safe, Aave, Kelp DAO or rsETH token contracts.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH