$7.8 Million Stolen in Ethereum Wallet Exploit via Uniswap v4 LP Safe Module
An Ethereum wallet holding leveraged rsETH has lost around $7.8 million after an attacker exploited a custom Safe module linked to a Uniswap v4 liquidity pool.
The incident happened on September 15, 2026, but security researchers said the attack did not come from a flaw in Kelp DAO's core rsETH contracts.
A custom Uniswap v4 LP Safe module used by the affected Gnosis Safe wallet had a public entry point that accepted caller-controlled data and used DELEGATECALL without proper access checks. This gave an outside attacker control over the wallet's assets, allowing them to redirect the wallet's tokens toward a malicious Hook pool.
The attacker attempted to extract the stolen rsETH through the Hook pool but was thwarted when an MEV bot known as 'yoink' detected and front-ran their transaction, capturing the entire $7.8 million worth of rsETH for itself.