Incident case file
Sign in to watchGnosis Safe Custom Module Exploit + MEV 'Yoink' Bot Interception — $7.73M
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 15, 2026, at 04:38:47 UTC (block 25,980,525), an attacker exploited a flaw in a custom Gnosis Safe module (not Safe's core code, not Kelp DAO's own infrastructure) belonging to an individual user. The module had a defective authorization check in a router's multicall/DELEGATECALL path, which the attacker abused to inject aEthrsETH into a maliciously-hooked Uniswap V4 pool, then swap and redeem the position. The nominal amount involved was approximately 2,900 rsETH (~$7.73-7.8M). Critically, an unrelated MEV bot known as 'Yoink' detected the same opportunity and front-ran the original attacker within the identical block, intercepting 2,882.37 rsETH before the original attacker could claim it. This means the headline loss figure does not reflect what the original attacker actually retained. Kelp DAO placed a 24-hour pause on the address that received the Yoink-captured funds as a precaution. No restitution to the victim has been reported.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)