Unnamed rsETH holder (Safe strategy module) hack — September 2026
Incident facts
| Date of incident | |
|---|---|
| Target type | Individual holder |
| Loss | $7,800,000Price at time of incident |
| Method | Access control flawA strategy-executor module authorised on the victim's Safe passed caller-supplied calldata into the Safe as a DELEGATECALL without checking who was calling, so anyone could run code in the Safe's context |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
A Safe multisig wallet belonging to a large holder of leveraged rsETH lost about 2,882 rsETH, roughly $7.8m, on 15 September 2026. The loss came from a third-party module installed on the wallet, not from Safe itself or from Kelp DAO, which issues rsETH.
The Safe had authorised a third-party strategy-executor module. Its recipe entry point passed calldata supplied by the caller into the Safe as a DELEGATECALL without checking who was calling, so anyone who could reach it could run code as the Safe. The attacker used it to route the Safe's Uniswap v4 liquidity module into a hooked pool they had created, which paired a worthless token they called the Permissionless Attacker Token against roughly 2,900 aEthrsETH. A custom hook unwrapped the aEthrsETH into rsETH that could be taken out. Blockaid, PeckShield and BlockSec confirmed the exploit.
The attacker sent the transaction through the public mempool, where an MEV bot known as yoink front-ran it and took the whole ~2,882 rsETH to an address of its own. Kelp DAO flagged that address and put it under a 24-hour pause so the rsETH could not move, and said its core contracts were secure and rsETH fully collateralised. The funds are gone from the victim either way; whether the bot's operator gives them back is open.
The amount is 2,882 rsETH at about $2,708, the CoinGecko rsETH price at the start of 15 September. Some reports put it at $7.73m, which is kept as the low end. Neither the wallet's owner nor the module's developer has been named.
Sources
- Metaverse PostSecondary · retrieved 2026-09-15
- CoinpediaSecondary · retrieved 2026-09-15
Changes to this entry
- Recorded on the day of the incident, so every figure is provisional. The amount values 2,882 rsETH at CoinGecko's price for the start of 15 September. If the MEV bot's operator returns the funds, the outcome and recovered amount will be updated.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Unnamed rsETH holder (Safe strategy module) hack — September 2026", iTokenly, accessed 2026-09-16, https://itokenly.com/hacks/rseth-safe-strategy-module-september-2026https://itokenly.com/hacks/rseth-safe-strategy-module-september-2026Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.