Gnosis Safe Wallet Drained of $7.8M Due to Flawed Auxiliary Contract
An attacker drained approximately $7.8 million worth of rsETH from a Gnosis Safe wallet on the Ethereum network.
The theft occurred early Tuesday, and security firms BlockSec, Blockaid, and SlowMist were able to trace the origin of the flaw to an external component authorized by the victim themselves.
The affected wallet was configured to allow an auxiliary contract to execute fund movements in an automated manner. However, this contract had a defective permission check that allowed any request naming the auxiliary contract itself as the destination to be approved.
An automated bot called 'yoink' front-ran the attack transaction and captured the tokens, sending 2,882 rsETH to a separate address.