Industry News

$7.8 Million Crypto Heist Backfires as Rival Bot Steals the Loot

Unchained · 16 Sept 2026
Key Takeaway If your business uses multisig wallets or crypto custody tools, regularly audit any third-party modules or plugins connected to them, since excessive permissions can create hidden backdoors even when the core wallet is secure.

An attacker drained roughly $7.8 million worth of rsETH tokens from an Ethereum Safe wallet by abusing a custom module the wallet's owner had approved. Security firm Blockaid confirmed the wallet's core security was not at fault; instead, a Multicall helper linked to a Uniswap v4 liquidity module treated certain self-referencing calls as automatically authorised, letting the attacker push instructions through as if they came from the wallet itself.

Before the attacker could collect the stolen funds, an automated trading bot known as Yoink spotted the pending transaction in the public mempool and paid roughly $46,000 to have its own transaction processed first in the same block. This let the bot capture the funds instead of the original attacker, redirecting about 2,882 rsETH to a new address.

Restaking protocol Kelp DAO responded quickly, freezing the address that received the funds within two hours and placing it under a 24-hour pause as a precaution. The protocol confirmed that rsETH remains fully backed and that normal minting and withdrawal operations were not affected by the incident.

Summarised by CISO AI from Unchained. We link back to every original so you can read it yourself.