tradingkey.logo
tradingkey.logo
Search

Kelp DAO suspends deposits and withdrawals as Gnosis wallet suffers $7.8M exploit

CryptopolitanSep 15, 2026 10:22 AM
facebooktwitterlinkedin
View all comments(0)

An unidentified Gnosis Safe wallet was exploited for nearly $7.8M in rsETH. The attack drained DeFi liquidity, leaving the token and vaults with worthless tokens. 

An attack was registered on September 15 against a Gnosis Safe wallet user, who has not yet been identified. The wallet was exploited for $7.73M in rsETH, according to Blockaid data. 

The wallet was drained in a single transaction, taking away the equivalent of 2,153 ETH, which was later split and moved across multiple wallets. The initial transaction shows the funds were finally parked in rsETH, without being swapped into ETH on the main chain for further laundering. 

This is the next major hack after the Bitcoin Pay hacker took 4,000 BTC from non-custodial user wallets. For September to date, decentralized hacks and exploits already surpass the level for the whole of August.

In the past three months, exploits have accelerated from their lows, showing more interest in AI-assisted hacks and targeting liquidity accumulation in DeFi protocols and specific vaults. 

Gnosis wallet exploited for $7.8M, Kelp DAO freezes the funds
Web3 hacks accelerated in September, already surpassing the levels from August. The recent exploit is the largest Web3 hack for the month. | Source: DeFi Llama

In September to date, a total of $326M was hacked, according to DeFi Llama data. Most of the attacks and exploits were under $1M, making the recent wallet exploit the biggest Web3 hack for September to date. 

How was the Gnosis wallet hacked?

The recent exploit involved a wrapped form of rsETH, which was then transformed into ETH and moved on-chain. The series of transactions showed the initial attacker and the MEV bot completed the transfers in a single block. 

Gnosis wallet exploited for $7.8M, Kelp DAO freezes the funds
The initial attacker moved rsETH out of the wallet’s vault, but the MEV bot Yoink took all the rsETH, ending up in one destination address. | Source: Etherscan

The initial wallet held leveraged rsETH in a Gnosis Safe, which authorized a whitelisted Safe module as a strategy executor to automate DeFi earnings. The trusted module turned out to be the entry point of the attack. A caller could exploit the Safe module with no extra authorization, since it was already whitelisted. 

What makes the attack even more complex is that the MEV bot Yoink front-ran the exploiter and took the ETH in the same block. The bot front-ran the withdrawal of ETH from rsETH, where the funds still remain in the form of rsETH. The bot’s destination address now contains only 44 ETH. 

Are other protocols affected by the exploit?

The bot’s destination address was flagged by Kelp DAO, leading to a freeze of all the deposited rsETH. KelpDAO announced the address would be frozen as a precaution to prevent further losses. 

Out of an abundance of caution, we’ve placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in or out of it.

We’re working closely with security experts to investigate and resolve this as quickly as possible. This is a precautionary, wallet-level measure only, announced Kelp DAO.

During the latest exploit, Kelp DAO so far avoided losses, stating all its vaults were safe. Previously, Kelp DAO lost $292M in rsETH, also affecting Aave vaults. The latest exploit is a rare case of intercepting the funds before being bridged to ETH and laundered through a mixer. 

At this point, the Yoink bot served as an inadvertent white hat hacker, salvaging the funds and allowing Kelp DAO to freeze the destination address. The activity of the Yoink bot, however, does not guarantee the return of the rsETH. 

As of September 15, rsETH traded at $2,663.68. However, Kelp DAO also suspended deposits and withdrawals to prevent the attacker or the bot from moving the funds out of the ecosystem.

The DAO already has a precedent with the previous hack, where a vote could revert some of the stolen funds. So far, the destination address has been blocked for 24 hours until a decision is made on clawing back the funds. 

Recently, Kelp DAO managed to recover its value locked to $1.06B after months of struggle following the recent exploit. The overall DeFi and lending recovery, with more funds available in vaults, may lead to more Web3 attacks against vulnerable contracts.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Disclaimer: The information provided on this website is for educational and informational purposes only and should not be considered financial or investment advice.

Comments (0)

Click the $ button, enter the symbol, and select to link a stock, ETF, or other ticker.

0/500
Commenting Guidelines
Loading...

Recommended Articles

tradingkey.logo
Risk Warning: Our Website and Mobile App provides only general information on certain investment products. Finsights does not provide, and the provision of such information must not be construed as Finsights providing, financial advice or recommendation for any investment product.
Investment products are subject to significant investment risks, including the possible loss of the principal amount invested and may not be suitable for everyone. Past performance of investment products is not indicative of their future performance.
Finsights may allow third party advertisers or affiliates to place or deliver advertisements on our Website or Mobile App or any part thereof and may be compensated by them based on your interaction with the advertisements.
© Copyright: FINSIGHTS MEDIA PTE. LTD. All Rights Reserved.