Kelp pauses rsETH transfers after $7.73 million Safe wallet attack

  • Kelp restricted rsETH transfers after attackers stole about $7.73 million from a Safe wallet.
  • Attackers exploited a connected module and routed assets through an attacker-created liquidity pool.
  • Safe-related add-on incidents also affected 86 wallets in May and Gnosis Pay in June.

Ethereum restaking protocol Kelp temporarily restricted rsETH transfers involving an address beginning with 0xc70f after a $7.73 million attack on a Safe wallet on Sept. 15, 2026. Blockaid said the attacker used a publicly callable keeper multicall and a custom Uniswap v4 liquidity module connected to an attacker-created hook pool, while SlowMist cited an authorization-check vulnerability in a related contract. The attack did not breach Safe's core multisignature design; it exploited a connected module that moved assets without the wallet owners' approval. The theft was the third Safe-related add-on incident reported this year, following a roughly $3 million loss from 86 wallets on May 25 and a Gnosis Pay security-feature bypass on June 1. Kelp said rsETH remains fully collateralized and its minting, withdrawals and external integrations continue normally.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.