EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Ethereum Safe Wallet lost US$7.73 million rsETH due to malicious modules and Uniswap V4 Hook

2026-09-15 20:30:51
Bookmark

以太坊 Safe 钱包因恶意模块与 Uniswap V4 Hook 损失约 773 万美元 rsETH

一名以太坊用户因攻击者利用 Safe 模块执行路径,将资产重定向至攻击者控制的 Uniswap v4 流动性池,导致约 773 万美元的 rsETH 资产损失。此次针对特定 Safe 地址的攻击发生于 9 月 15 日凌晨,安全监控识别出两笔引发资产流失的交易。现有证据表明,问题根源在于该钱包的自定义模块与恶意 Hook 之间的交互,而非 Safe 核心智能账户合约存在漏洞。

自定义模块将资产路由至恶意池

此次攻击利用了公共 Keeper 的多调用(multicall)机制,调用了绑定在该账户上的自定义 Uni V4 LP Safe 模块。执行过程将流动性引导至一个由攻击者控制 Hook 创建的 Uniswap v4 池中,从而使恶意路由逻辑能够访问该头寸涉及的资产。

随后,该 Hook 将受害者的 aEthrsETH 头寸转换为可转移的 rsETH。aEthrsETH 代表存入 Aave 的 rsETH,这意味着在提取底层 rsETH 之前,攻击者必须先将该头寸从其 Aave 收据代币形式中移出。

Safe 的模块架构允许授权扩展独立于常规多重签名流程执行交易。虽然模块可以自动化复杂的 DeFi 操作,但 Safe 警告称,这些模块具有极高的安全性风险,因为启用恶意或有漏洞的模块可能导致账户执行任意交易。

The attack did not promise Safe's core multi-signature contracts, signature keys or the Ethereum network itself. The identified failure paths involve custom modules for the account and Uniswap v4 Hook controlled by the attacker. A similar situation occurred in the previous SquidRouter module vulnerability in May, when the vulnerability cleared funds from 86 Safe accounts on the Ethereum and Base networks, but the underlying Safe contract was not affected.

MEV Robot Capture and Extraction Process

A MEV (Maximum Extractable Value) operation linked to an address marked by Etherscan as "MEV Frontrunner Yoink" intercepted the attack transaction within the block. The robot preached the original extraction transaction and captured a profitable transaction path before the attacker completed the commit. Although the change in transaction order caused the external address to eventually intercept most of the extracted value, the victim still lost rsETH because the underlying malicious execution was successful.

In the end, the Safe Wallet retained only liquidity positions NFT from the malicious pool, and no longer held previously held positions backed by rsETH.

rsETH refocuses on security issues

rsETH is a liquidity pledge token launched by Kelp DAO and is currently widely integrated in the Ethereum lending and liquidity markets. Its use in Aave led to the aEthrsETH collateral involved in this latest wallet theft incident. In April this year, Kelp DAO suffered a major security outage, releasing approximately $292 million in rsETH from cross-chain infrastructure and creating huge downstream exposure in the DeFi lending market.

The loss on September 15 was an independent incident. Current evidence focuses on the module execution of individual Safe, the attacker's controlled Uniswap v4 Hook, and the resulting rsETH position conversion supported by the wallet Aave. No broader compromise has been found for Safe, Aave, Kelp DAO or rsETH token contracts.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP