Exploit rsETH on Ethereum: a Safe wallet loses $7.73 million
A Safe wallet has lost approximately $7.73 million in rsETH within a few hours, falling victim to an rsETH exploit on Ethereum that leveraged a public function of the Uniswap v4 protocol to redirect funds to a pool specifically created by the attacker. The news, reported by the security firm Blockaid, brings attention to the risks associated with custom modules interacting with Uniswap v4's "hooks," the latest programmable version of the decentralized exchange protocol.
Key Points
- An unidentified user of a Safe wallet has suffered an estimated loss of $7.73 million in rsETH.
- The attack exploited a public multicall keeper to target a custom liquidity provider module on Uniswap v4.
- The funds were funneled into a hooked pool created by the attacker.
- The protocol involved is Uniswap version 4, which introduces programmable hooks in liquidity pools.
Loss of $7.73 million in rsETH due to an exploit on Ethereum
According to Blockaid, the victim was a user managing funds through a multisig Safe wallet, one of the most commonly used tools for the secure custody of crypto assets by individuals and institutions. Despite the typical protections of a multisig infrastructure, the attack managed to siphon off the equivalent of $7.73 million in rsETH, the liquid staking token associated with Ethereum.
Users and Assets Involved
The target of the attack remains anonymous, and Blockaid did not specify how the attacker was able to operate on a module linked to the wallet. The affected token, rsETH, represents a share of ETH staked through liquid staking protocols, a segment of decentralized finance that has attracted increasing capital in recent years due to its promise of immediate liquidity on otherwise locked assets.
Economic Impact of the Attack
The amount stolen, nearly $7.8 million, places this incident among the most significant exploits in recent months related to the Ethereum ecosystem. Why it matters: incidents like this target tools considered the safest, multisig wallets, demonstrating that custody security is insufficient if the modules or contracts they interact with are compromised upstream.
How the Attacker Operated: the Public Keeper Multicall
The attacker used a public multicall keeper, a function accessible to anyone, to target a custom liquidity provider module built on top of Uniswap v4.
The Targeted Liquidity Provider Module of Uniswap v4
Uniswap v4 introduced a hook-based architecture, additional contracts that allow developers to customize the behavior of liquidity pools. This flexibility, while paving the way for dynamic fee mechanisms or advanced strategies for liquidity providers, also multiplies the potential attack surfaces when modules are not designed with adequate access controls.
How the Keeper Multicall Works
In this specific case, the keeper multicall function was intended to automate routine operations on the liquidity provider module. The problem is that, being public, anyone could invoke it, including the attacker, who used it to force the redirection of assets to an unauthorized destination.
-- Price
Funds Funneled into a Hooked Pool Created by the Attacker
Once the exploit was activated, the stolen funds were channeled into a hooked pool specifically built by the attacker within the same Uniswap v4 framework.
Details of the Hooked Pool
This pool, created specifically to absorb the stolen funds, exploited the same hook infrastructure that makes Uniswap v4 flexible for legitimate developers. In practice, the attacker replicated the protocol's logic to their advantage, turning a tool designed for liquidity customization into a channel for theft collection.
What It Means for Uniswap v4 Security
The incident comes at a time when Uniswap v4 continues to expand its ecosystem of custom hooks by third parties. Why it matters: the security of the entire framework depends not only on the base code of the protocol but also on the quality of the modules built on top of it by external developers. A single poorly designed module, like the one exploited in this attack, can be enough to drain millions of dollars, even when assets are held through tools considered robust like Safe multisig wallets.
FAQ
What was the economic impact of the exploit on Ethereum for the Safe wallet user?
The Safe wallet user lost approximately $7.73 million in rsETH due to the exploit.
Which protocol and module were targeted in the attack?
A custom liquidity provider module within the Uniswap version 4 protocol was hit.
How did the hacker execute the attack?
The attacker exploited a public function called keeper multicall to redirect the funds.
Where were the stolen funds directed during the attack?
The funds were funneled into a hooked pool specifically created by the attacker.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Solana Dominates Ethereum on Fees, but ETH Maintains Lead on Burn

Bitwise survey finds 1%-2% crypto allocations dominate

BTC Share Drops to 44.2%, ETH Share in the Americas Rises to 38.5%

Kalshi Denies Investigation by the U.S. CFTC into Its Trading Activities

Coinbase plans post-quantum Bitcoin custody for any scheme

Bitcoin Layer Citrea Acquires Privacy Wallet Crest

SharpLink CEO Predicts AI Agents Will Reshape Financial System, Creating $4 Trillion Value by 2035

SharpLink CEO Predicts AI-Driven Trading Will Focus on Ethereum Ecosystem

EU Financial Regulators Warn of Quantum Computing Threats to Blockchain Security

Aave V4 Attracts $1.2 Billion in Deposits, Founder Responds to Concerns

Zest Protocol Launches Bitcoin Collateral Vaults Mainnet Demo

AI and Crypto: Why BlackRock Sees a Major Convergence

US Spot Ethereum ETFs See 270 Million Net Inflows Led by BlackRock

iPhone App Leads to Crypto Theft of Half a Million Euros - Here's What We Know Now

Coinmetrics Report: The Competition of Tokenized Stocks and Their Future Development Path

ETH, SOL burn totals do not reflect true supply change

CME Plans BCH and UNI Futures on October 19 | WEEX TradFi Daily Brief (September 23, 2026)
Global markets on September 23 focus on a Nasdaq high and an expansion of crypto futures. The Nasdaq closed higher on September 22 for a second straight closing high. Memory names such as Micron and SanDisk plus AI hardware lifted risk appetite. Brent eased to about $98 and WTI to about $94.6. Bitcoin was near $86,200 and Ethereum near $2,750. Investors are watching CME’s planned October 19 BCH/UNI futures and the impact of delayed compute-futures review on NVDA and CME.

WEEX Exclusive:CME Plans BCH and UNI Futures on October 19 | WEEX TradFi Daily Brief (September 23, 2026)

Vitalik Buterin: Blockchain Has Evolved into a Cryptographically Secure Computing Network

Puffer Partners with Google Cloud to Support UniFi Infrastructure

21Shares Launches First Zcash ETP and ETHFI ETP

Moscow Exchange Launches Perpetual Futures for Bitcoin, Ethereum, Solana, XRP, and Tron

Can UNI Reach $12 After CME Announces Uniswap Futures?
Can UNI reach $12 after CME announces Uniswap futures? Explore UNI price levels, market catalysts, risks, and how to buy and trade UNI on WEEX.

0G Labs Launches 0G Hub Integrating Cross-Chain, Trading, and Application Discovery

Mantle Tokenized Assets Exceed 1340

Camelot and Cypher Merge to Form Frontier, Focusing on Uniswap v4 Infrastructure

Kalshi Ethereum Perpetual Futures Trading Volume 57% from Same Size Orders - CoinDesk

21Shares: Privacy coins grow nearly 5x in one year

EURC scam: Dutch police arrest 2 over fake Rolex deals









