Safe Wallet Module Vulnerability Leads to $7.73 Million Loss
A Safe wallet lost approximately $7.73 million on September 15, 2026, due to a vulnerability in one of its modules.
The wallet was a multisig, which is designed to be highly secure, requiring multiple signatures for transactions. However, the owners had enabled a module that allowed arbitrary transactions without the usual signature threshold, leaving the wallet vulnerable to attacks.
The attack occurred through a bespoke module used for a liquidity strategy on Uniswap v4. The attacker exploited the DELEGATECALL function, which executes foreign program code in the storage and under the identity of the contract itself.