
Uniswap V4 hook exploit drains $7.73M in rsETH from a Safe wallet through a public keeper and malicious hooked pool.
Author: Kritika Gupta
15th September 2026- An attacker drained about $7.73 million in rsETH from a single Ethereum Safe wallet. Then an MEV bot front-ran the theft in the same block. Security firm Blockaid flagged the rsETH exploit at 05:32 UTC, hours after the funds moved.
High Signal Summary For A Quick Glance
The Block
@TheBlockCo
THE BLOCK: An unidentified Safe wallet user lost about $7.73 million worth of rsETH in an Ethereum exploit, according to Blockaid. The attacker used a public keeper multicall to target a custom Uniswap v4 liquidity provider module and route it into an attacker-created hooked https://t.co/MlZOCIgG8W

07:37 AM·Sep 15, 2026
LEMON_MAHEDY
@LEMON_MAHEDY
$7.73M rsETH Drained From Ethereum Safe in Uniswap V4 Hook Exploit > An attacker manipulated a public keeper multicall to push a Safe module into a malicious Uni V4 hooked pool, which unwrapped aEthrsETH to rsETH before MEV bots extracted the funds in the same block. https://t.co/44EPHeXj5f
🚨Blockaid exploit detection system detected an exploit on an unidentified user's Safe on Ethereum. ~$7.73M confirmed rsETH loss so far. An attacker used a public keeper multicall to drive a custom Uni V4 LP Safe module into an attacker-created hooked pool; the hook unwrapped
07:18 AM·Sep 15, 2026
High attention and emotional sentiment detected.
According to Blockaid, the attacker targeted one wallet’s configuration rather than any core protocol. Kelp DAO, the issuer of rsETH, quickly paused the address holding the stolen tokens. It also stressed that its contracts remain safe.
The victim Safe had enabled a custom Uniswap V4 liquidity module. That module was allowed to move the wallet’s assets without a fresh multisig signature on every call.
Next, the attacker used a public keeper multicall to drive that module. Because the path was permissionless, anyone could trigger it. The attacker then pointed the module at a Uniswap V4 pool they had created, one that carried a malicious hook.
Finally, the hook unwrapped aEthrsETH into raw rsETH. In effect, it burned Aave’s interest-bearing receipt token and withdrew the underlying rsETH. As a result, the tokens became a freely transferable asset that could leave the Safe’s control.
The full drain happened around 04:38 UTC in block 25980525. Blockaid’s figure of $7.73 million matches roughly 2,882 rsETH at recent prices.
Here is the twist that set this incident apart. The original attacker built the path, yet a separate MEV bot named Yoink captured the value first.
Yoink front-ran the extraction in the same block. Therefore the bot, not the original attacker, ended up controlling the proceeds. PeckShield put the intercepted total at about $7.81 million, a slightly higher print than Blockaid’s due to price timing.
So far, there is no public confirmation that Yoink has returned the funds. Analyst Vishal Chawla, summarizing PeckShield, said a return is expected but not committed.
Attack sequence and response on September 15, 2026
The attacker creates a Uniswap V4 pool containing a malicious custom hook.
The victim’s Safe is connected to a custom Uniswap V4 LP module with a public keeper multicall.
The attacker activates the module and routes its execution through the malicious hooked pool.
The hook unwraps aEthrsETH into rsETH, while the Yoink MEV bot front-runs the transaction and extracts the proceeds.
Blockaid publicly identifies the Safe drain and outlines the malicious module and hooked-pool attack path.
Further statements from Safe, the victim and involved teams are pending, along with confirmation of any fund recovery.
Roughly 2,882 rsETH now rests at the address 0xC70f00CD...80ea0. PeckShield confirmed the funds currently sit there. So far, no evidence points to a mixer, an exchange deposit, or a bridge.
Shortly after, Kelp DAO placed that address under a temporary 24-hour pause. During that window, rsETH cannot move in or out of it.
Meanwhile, Kelp said its contracts are safe and rsETH stays fully backed. It added that minting, withdrawals, and integrations all run normally, so no user action is required.
A Safe is a smart-contract wallet, and owners can enable modules to automate tasks. However, a module with broad permissions can also move the tokens a wallet holds. That power is exactly what this rsETH exploit abused.
According to secondary write-up Telem News, the loss stemmed from module authorization abuse within the victim’s account. It did not stem from a flaw in Safe’s core protocol. Blockaid’s framing points the same way.
Still, some open questions remain. Blockaid has not published verified addresses for the custom module or the malicious hook. Consequently, the exact misconfiguration stays partly inferred for now.
On-chain anatomy of the Uniswap V4 hook exploit
Uniswap V4 lets any pool attach a hook contract that runs custom code during swaps or liquidity changes. Moreover, pool creation is permissionless, so anyone can deploy a pool whose hook runs attacker logic.
This is not the first hook-linked loss. Trail of Bits has cited two recent cases. The Cork incident lost near $12 million in May 2025. The Bunni hook loss hit $8.4 million in September 2025. Both were application-level failures, not a break in the Uniswap V4 core.
The pattern echoes earlier Safe module trouble too. In May 2026, a third-party SquidRouterModule drained about $3.2 million from 86 Safes through overly broad permissions.
Despite the headlines, there is no sign of an rsETH depeg tied to this drain. The theft hit one wallet, not the roughly $1.06 billion token supply behind rsETH.
According to DefiLlama, rsETH traded near $2,685 with a 24-hour move of about -0.59%. Kelp’s total value locked sat around $1.09 billion, up 26.2% over 30 days.
For context, some users quickly linked this event to April’s $292 million Kelp bridge hack. That comparison misleads, though. April involved unbacked minting through a forged bridge message, while today’s rsETH exploit drained already-backed tokens from one Safe.
Several answers are still pending. Investigators have not named the attacker. No one has confirmed whether Yoink will return the funds when the pause lifts.
For now, the takeaway is practical. A Safe wallet is only as safe as the modules its owner enables. Permissionless V4 hooks also remain an attack surface worth watching. Traders and treasuries should audit every module and keeper that can touch their funds.
This article is informational and not financial advice. Always verify on-chain data and manage risk before interacting with any DeFi protocol.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.