DEV Community

Cover image for The Hacker Who Lost $7.73M to a Bot — rsETH Safe Module Exploit
mehvetero
mehvetero

Posted on

The Hacker Who Lost $7.73M to a Bot — rsETH Safe Module Exploit

On September 15, 2026, someone found a bug in a custom router module attached to a Gnosis Safe holding over $7.73 million in Aave-wrapped rsETH. They built the exploit, submitted it to the mempool — and an MEV bot named Yoink copied the transaction and executed it first. The attacker showed up an hour later to scrape leftovers.

This write-up covers what I was able to verify on-chain and what I had to rely on others for. The router's source code is not published on Etherscan, so the internal vulnerability mechanism comes from SlowMist's bytecode analysis, credited below. Everything else — the Safe configuration, the money flow, the attacker timeline, and the current state — I read directly from the chain.

All read : https://x.com/mehvetero/status/2100007912953491857

Top comments (0)