Exploit rsETH on Ethereum: a Safe wallet loses $7.73 million
A Safe wallet has lost approximately $7.73 million in rsETH within a few hours, falling victim to an rsETH exploit on Ethereum that leveraged a public function of the Uniswap v4 protocol to redirect funds to a pool specifically created by the attacker. The news, reported by the security firm Blockaid, brings attention to the risks associated with custom modules interacting with Uniswap v4's "hooks," the latest programmable version of the decentralized exchange protocol.
Key Points
- An unidentified user of a Safe wallet has suffered an estimated loss of $7.73 million in rsETH.
- The attack exploited a public multicall keeper to target a custom liquidity provider module on Uniswap v4.
- The funds were funneled into a hooked pool created by the attacker.
- The protocol involved is Uniswap version 4, which introduces programmable hooks in liquidity pools.
Loss of $7.73 million in rsETH due to an exploit on Ethereum
According to Blockaid, the victim was a user managing funds through a multisig Safe wallet, one of the most commonly used tools for the secure custody of crypto assets by individuals and institutions. Despite the typical protections of a multisig infrastructure, the attack managed to siphon off the equivalent of $7.73 million in rsETH, the liquid staking token associated with Ethereum.
Users and Assets Involved
The target of the attack remains anonymous, and Blockaid did not specify how the attacker was able to operate on a module linked to the wallet. The affected token, rsETH, represents a share of ETH staked through liquid staking protocols, a segment of decentralized finance that has attracted increasing capital in recent years due to its promise of immediate liquidity on otherwise locked assets.
Economic Impact of the Attack
The amount stolen, nearly $7.8 million, places this incident among the most significant exploits in recent months related to the Ethereum ecosystem. Why it matters: incidents like this target tools considered the safest, multisig wallets, demonstrating that custody security is insufficient if the modules or contracts they interact with are compromised upstream.
How the Attacker Operated: the Public Keeper Multicall
The attacker used a public multicall keeper, a function accessible to anyone, to target a custom liquidity provider module built on top of Uniswap v4.
The Targeted Liquidity Provider Module of Uniswap v4
Uniswap v4 introduced a hook-based architecture, additional contracts that allow developers to customize the behavior of liquidity pools. This flexibility, while paving the way for dynamic fee mechanisms or advanced strategies for liquidity providers, also multiplies the potential attack surfaces when modules are not designed with adequate access controls.
How the Keeper Multicall Works
In this specific case, the keeper multicall function was intended to automate routine operations on the liquidity provider module. The problem is that, being public, anyone could invoke it, including the attacker, who used it to force the redirection of assets to an unauthorized destination.
-- Price
Funds Funneled into a Hooked Pool Created by the Attacker
Once the exploit was activated, the stolen funds were channeled into a hooked pool specifically built by the attacker within the same Uniswap v4 framework.
Details of the Hooked Pool
This pool, created specifically to absorb the stolen funds, exploited the same hook infrastructure that makes Uniswap v4 flexible for legitimate developers. In practice, the attacker replicated the protocol's logic to their advantage, turning a tool designed for liquidity customization into a channel for theft collection.
What It Means for Uniswap v4 Security
The incident comes at a time when Uniswap v4 continues to expand its ecosystem of custom hooks by third parties. Why it matters: the security of the entire framework depends not only on the base code of the protocol but also on the quality of the modules built on top of it by external developers. A single poorly designed module, like the one exploited in this attack, can be enough to drain millions of dollars, even when assets are held through tools considered robust like Safe multisig wallets.
FAQ
What was the economic impact of the exploit on Ethereum for the Safe wallet user?
The Safe wallet user lost approximately $7.73 million in rsETH due to the exploit.
Which protocol and module were targeted in the attack?
A custom liquidity provider module within the Uniswap version 4 protocol was hit.
How did the hacker execute the attack?
The attacker exploited a public function called keeper multicall to redirect the funds.
Where were the stolen funds directed during the attack?
The funds were funneled into a hooked pool specifically created by the attacker.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

$140.6 Million Exits from Ethereum ETFs, $60.7 Million Inflows to Solana

BlackRock Transfers 54,096 ETH and 2,015 BTC to Coinbase Prime

RISEx Proposes 20% Retention Condition for Stolen Funds

Best Crypto Exchange in Italy in 2026: What to Choose for Systematic Trading

Ethereum co-founder Vitalik Buterin argues that local AI can protect your privacy without losing speed

Ethereum Spot ETF Sees $144 Million Net Inflow Yesterday, BlackRock's ETHA Leads with $114 Million

Fake AI trading bot tutorials steal 274.6 ETH from 224 victims

Bitwise Evaluates Clarity Act's Failure as a Speed Bump

Morpho Opens Borrowing Against Coinbase's Tokenized Stocks

Your crypto hardware wallet can stay secure while everything around it fails

Concrete Establishes Foundation and Launches Governance Token CT

Deutsche Bank to Launch Cryptocurrency Custody Services by Year-End for Corporate and Institutional Investors

Ethereum: 'Any teenager' can derail the Glamsterdam test

Arc Launches AI Programming Tool Arc Studio Supporting Natural Language Generation for On-Chain Applications

Renaiss Completes TCG Card Machine Application Integration with GIWATER, Becoming the First DEX in Korea to Connect

Attackers Use Testnet ETH to Win Sepolia Block Auction

Shareholders Lose Approximately $50 Billion, Investors Scrutinize Compensation and Related Transactions

Ethereum Glamsterdam Completes Devnet-11 Drill, Gas Limit Proposed to Increase to 200 Million

Toss Completes Blockchain-Based Payment Technology Verification with Korea Minting and Security Printing Corporation

After Congress killed its landmark crypto bill, the SEC unlocked the $77 trillion US stock market through tokenization

Optimism approves Upgrade 20 for Superchain interoperability

Trader Royal Kane advises against investing in XRP due to high market cap

Ethereum Institutional Forum EIF III to be Held in London on November 12

Telcoin (TEL): Where Does the First Regulated Crypto Bank in the US Stand?

BIS Calls Blockchain Indicators 'Noise' Rather Than Accurate Metrics. Why?

JPYC Suspends Ethereum Issuance Reservations, Investigating Cause of Malfunction

Ethereum EIP-8198 Proposal Reduces Block Time to 10 Seconds

Historic Decision by SEC: What Does It Mean for the Crypto Sector?

Bitcoin Core 32.0 Enters Final Phase Before Scheduled Release on October 10











