Meet the Top 101 in Crypto
News
3 min read

One Coding Mistake Exposed $7.8M in Crypto — A Bot Paid $47K to Steal It First

Published 18 September 2026
Dr. Guneet Kaur
Authors

Key Takeaways

  • A flawed authorization check in a custom module attached to an Ethereum Safe wallet exposed roughly 2,900 rsETH worth $7.8 million.
  • An MEV bot called Yoink spotted the attack in Ethereum’s public mempool and paid about $46,000–$47,000 to execute first.
  • Safe’s core contracts and Kelp DAO’s rsETH contracts were not compromised; the weakness was in custom infrastructure authorized by the wallet.

A hacker found a coding error that could drain $7.8 million from an Ethereum wallet. Then another bot spotted the attack and stole the payout first.

The unusual exploit unfolded on Sept. 15 when an attacker targeted an Ethereum Safe holding roughly 2,900 rsETH, Kelp DAO’s liquid restaking token.

Security researchers traced the vulnerability to a custom helper contract that had been authorized to interact with the Safe. A faulty authorization check effectively allowed an unauthorized caller to make malicious instructions appear trusted.

This matters: researchers said Safe itself was not hacked, and there is no indication the wallet owners’ private keys were compromised.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Unlock 1,500+ cryptocurrencies and seamless instant swaps in the all-in-one crypto super app ChangeNOW
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217

One Authorization Error Opened a $7.8M Wallet

Safe wallets can use modules to automate transactions without requiring owners to sign every action.

In this case, that convenience became the attack surface.

The helper contract’s authorization logic approved calls under conditions that could be manipulated by pointing the transaction back toward the trusted contract itself.

That gave the attacker a route into an enabled Safe module and ultimately allowed code to execute in the wallet’s context.

The attacker then routed the Safe’s position through a malicious Uniswap v4 pool and hook.

Around 2,900 aEthrsETH was moved into the pool and converted into transferable rsETH, worth approximately $7.8 million at the time.

But the attacker made another mistake.

The exploit transaction was sent through Ethereum’s public mempool, exposing the profitable opportunity before it was confirmed.

‘Yoink’ Pays $47K to Get There First

An MEV searcher, appropriately labeled “Yoink,” detected the pending transaction and copied the opportunity.

The bot paid roughly $46,000–$47,000 to secure priority execution and get its transaction processed first. It captured about 2,882.37 rsETH, while another 17.63 rsETH was swapped during the transaction.

Consequently, the original attacker’s main transaction failed to secure the $7.8 million prize.

The story did not completely end there. A later reconstruction found the attacker returned roughly 69 minutes later and extracted about 23.69 ETH, worth around $58,000 at the time, using another helper contract.

Kelp DAO Says rsETH Remains Backed

Kelp DAO responded by temporarily restricting the address that received the rsETH.

The project said its underlying contracts were unaffected and that rsETH remained fully backed, while normal operations continued.

The incident, therefore, wasn’t a failure of rsETH or Safe’s core wallet code.

Instead, roughly $7.8 million was exposed because a custom contract trusted by the wallet contained a faulty permission check, a reminder that a multisig can only be as secure as the modules it authorizes.

 

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Dr. Guneet Kaur

Dr. Guneet Kaur is a senior editor at CCN.com and a Science Fellow at Exponential Science. She is a fintech and blockchain expert with extensive experience in digital finance education, blockchain ecosystems, and cryptocurrency markets. She has worked with global media such as Cointelegraph, as well as education and blockchain platforms, to design and lead strategic content and learning initiatives. As an educator and assessor for top-tier executive programs, she bridges real-world fintech trends with academic insight.

Dr. Kaur is also a published researcher and peer reviewer across fintech and data science journals, including Financial Innovation Journal and International Journal of Big Data Intelligence and Applications. Her work spans data-driven analysis, Web3 innovation, and technical content development. With a strong foundation in both industry and academia, she translates complex financial technologies into practical applications, empowering learners, professionals, and institutions across the rapidly evolving digital finance landscape.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status