A hacker attempting to steal 1.2 billion yen worth of cryptocurrency was caught by a bot that stole the entire amount by a matter of seconds. | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker




A hacker exploited Safe, Ethereum’s safe wallet, to steal digital assets worth 2,900 rsETH (approximately $7.8 million: 1.2 billion yen). However, the hacker’s stolen digital assets were then taken over by a bot.

Safe Module Drain: 2,900 rsETH Taken in One Ethereum Block | Bitquery – Bitquery

https://bitquery.io/investigations/rseth-safe-module-drain

A Bot Robbed the Hacker Who Drained $7.8 Million in rsETH From a Safe Wallet – Unchained
https://unchainedcrypto.com/a-bot-robbed-the-hacker-who-drained-7-8-million-in-rseth-from-a-safe-wallet/

In the early morning of Tuesday, September 15, 2026 (UTC), hackers stole approximately $7.8 million worth of rsETH from the Ethereum wallet Safe. rsETH is a Liquid Restaking Token (LRT) issued by Kelp DAO . The stolen $7.8 million worth of rsETH was seized by a bot that was monitoring the menpool , a waiting area for pending transactions.

Blockaid , a security platform for preventing fraud and hacking in the cryptocurrency ecosystem, was the first to detect the hacker theft of rsETH. Blockaid reported, ‘Our exploit detection system detected an exploit on an unverified user’s Safe (formerly Gnosis Safe) on Ethereum. To date, approximately $7.73 million (approximately 1.2 billion yen) worth of rsETH has been confirmed to have been lost. The attacker exploited Keeper’s multicall to redirect their own Uni V4 LP Safe module to a hooked pool created by the attacker. This hook unwrapped aEthrsETH into rsETH. Yoink then used MEV within the same block to extract the funds.’

Yoink is an MEV bot that automatically searches for opportunities to profit by exploiting the order of transactions. Yoink preempts the attacker’s own transactions, paying the block creator approximately $46,000 (approximately 7.1 million yen) to have the transactions processed preferentially, thereby siphoning off funds stolen by the hacker.

According to Blockaid, the hack was not due to a flaw in the Safe core or the owner’s private key, but rather an exploitation of the authorization path of an auxiliary contract connected to the Safe. Researchers at security firms BlockSec, SlowMist, and AstraSec have confirmed that this was due to a flaw in an auxiliary contract called ‘multicall’ that the wallet owner had authorized for use.

According to security researchers, ‘multicall’ treated all operations that specified its own address as the caller as pre-approved. As a result, external attackers could send commands through the module and have them processed as legitimate commands executed by Safe.

Safe’s multi-signature wallet allows owners to add third-party modules. These modules have the authority to move funds without the need to collect multiple signatures, which is normally required. In this case, the Uni V4 LP Safe module, which was developed independently, apparently had an exposed entry point that allowed an attacker to forward a specified command to the wallet. The attacker created a transaction to ‘withdraw aEthrsETH held by the wallet and acquire it as rsETH’ and sent it to a public member pool.

However, Yoink detected the attacker’s transaction and preemptively executed the same transaction, acquiring 2900 rsETH. Yoink then sent 2882.37 rsETH to another address and exchanged 17.63 rsETH for 18.95 ETH. Subsequently, Kelp DAO froze the address within two hours. Kelp DAO explained, ‘As a precaution, we temporarily suspended this address for 24 hours.’

This leaves the funds in limbo. It is unclear whether Yoink will return the funds, but in the January 2026 attack on Makina, MEV builders received approximately 10% of the stolen digital assets as rewards and returned the rest to their original owners.





Click Here For The Original Source.

——————————————————–

..........

.

.