BTCETHBNBSOLXRPUSDCTRXADADOGE
Data by CoinGecko
Scam WatchBearish

Bot Intercepts $7.8 Million From Multisig Wallet Exploit

Early Tuesday, an attacker orchestrated a theft of approximately $7.8 million in cryptocurrency from a multisignature wallet, only to lose the entire payout to an automated bot observing the network. The bot detected the malicious transaction and intercepted the haul, moving the assets to a new address before the original hacker could claim them.

The incident, initially detected by blockchain security firm Blockaid, involved an Ethereum Safe wallet at 04:38 UTC. The original attacker targeted roughly 2,900 rsETH. However, because the attacker’s instructions were broadcast publicly in the mempool, a generalized maximum extractable value (MEV) searcher known as Yoink spotted the impending exploit. Yoink paid the block’s builder a $46,000 fee to guarantee its own transaction was ordered first. By front-running the attacker in the exact same block, the bot successfully walked away with 2,882 rsETH.

Faulty Third-Party Modules

The core infrastructure of the multisignature wallet was never compromised. Instead, investigators from BlockSec, SlowMist, and AstraSec determined the vulnerability originated from a Multicall helper approved by the wallet’s owner. Multisignature platforms allow users to attach third-party modules to move funds without requiring standard signature collections.

In this instance, a customized Uniswap v4 liquidity module contained an exposed entry point. The helper automatically pre-authorized any call pointing back to its own address. This allowed the attacker to funnel malicious instructions through the module, prompting the wallet to unwrap yield-bearing aEthrsETH into standard rsETH. The funds were then directed to a pool controlled by the attacker, leaving only worthless receipts.

Bot Intercepts $7.8 Million From Multisig Wallet Exploit
module-authorization abuse on that Safe, not a Safe core / owner-key bug,

Blockaid clarified the event was "module-authorization abuse on that Safe, not a Safe core / owner-key bug," noting the primary smart contracts simply executed what the approved module requested.

Funds Placed on Ice

Following the interception, the Yoink bot routed the 2,882 rsETH to a fresh address. Within two hours, Kelp DAO, the restaking protocol behind the token, intervened to freeze the destination address. The protocol confirmed that minting and withdrawals were operating normally and stated the asset "remains fully backed."

"Out of an abundance of caution, we’ve placed that address under a temporary 24-hour pause," the protocol noted.

The ultimate fate of the intercepted funds remains unresolved, though a recent precedent exists for MEV bots returning assets. In January, an MEV builder captured funds during a Makina exploit and subsequently returned 920 out of 1,023 ether, retaining a 10 percent reward under the SEAL Whitehat Safe Harbor arrangement.

The incident adds to a broader pattern of losses stemming from trusted external infrastructure rather than foundational code flaws across decentralized finance. Similar vulnerabilities led to an $8.7 million loss for Moonwell in August, and Kelp DAO's restaking token was previously swept up in a $292 million bridge exploit in April.

← All stories