$7.8M Lost as Attacker Exploits Whitelisted Module in Gnosis Safe Wallet
A $7.8 million loss occurred on September 15, 2026, when an attacker routed a custom liquidity provider module attached to a Gnosis Safe wallet through their own Uniswap v4 pool.
The module was whitelisted as a strategy-executor and exposed a recipe entrypoint that allowed the caller to execute arbitrary code inside the Safe's execution context. This allowed the attacker to move funds without requiring the Safe's signature threshold or owner set to sign.
A Maximal Extractable Value (MEV) bot named Yoink front-ran the exploit in the same Ethereum block, capturing the position and moving the bulk of the tokens to a new receiving address. The bot then sent 2,882.37 rsETH, valued at $7,800,883.70, to another address.
Kelp DAO responded by placing a 24-hour wallet-level pause on the receiving address, confirming that its core contracts and rsETH backing remained unaffected. This precautionary measure only isolated the funds within Kelp's window, as the 17.63 rsETH already sold on Uniswap v4 and the later routed 157.71 rsETH through Fluid Dex sat outside the freeze.