Uniswap v4 Module Exploit Results in $7.73M rsETH Loss
A recent exploit of Uniswap's version 4 liquidity provider module resulted in a loss of $7.73 million worth of rsETH for an unidentified Safe wallet user.
The attack, which was flagged by blockchain security firm Blockaid, leveraged a public keeper multicall function to target the custom module built on top of Uniswap v4's architecture.
The stolen funds were routed into an attacker-created hooked pool using Uniswap v4's hooks feature. This incident highlights the risks associated with interacting with newer, custom-built DeFi modules and the importance of tightly scoped permissions and access controls.