Ethereum restaking protocol Kelp temporarily restricted rsETH transfers involving an address beginning with 0xc70f after a $7.73 million attack on a Safe wallet on Sept. 15, 2026. Blockaid said the attacker used a publicly callable keeper multicall and a custom Uniswap v4 liquidity module connected to an attacker-created hook pool, while SlowMist cited an authorization-check vulnerability in a related contract. The attack did not breach Safe's core multisignature design; it exploited a connected module that moved assets without the wallet owners' approval. The theft was the third Safe-related add-on incident reported this year, following a roughly $3 million loss from 86 wallets on May 25 and a Gnosis Pay security-feature bypass on June 1. Kelp said rsETH remains fully collateralized and its minting, withdrawals and external integrations continue normally.