Kelp DAO Freezes rsETH After $7.8M Gnosis Safe Wallet Exploit

Key Takeaways
- An unidentified Gnosis Safe wallet was exploited for nearly $7.8 million in rsETH on September 15.
- The Yoink MEV bot front-ran the attacker, intercepting funds before they could be laundered into ETH.
- Kelp DAO placed a 24-hour freeze on the destination address and suspended rsETH deposits and withdrawals.
- September's total hack losses reached $326 million, surpassing August's figures.
- Kelp DAO previously lost $292 million in rsETH and has since recovered its TVL to $1.06 billion.
$7.8M Exploit Hits Gnosis Safe Wallet
An unidentified Gnosis Safe wallet was exploited for nearly $7.8 million in rsETH on September 15, according to data from Blockaid. The attacker drained the wallet in a single transaction, making off with approximately 2,153 ETH worth of tokens.
The stolen funds were quickly split and moved across multiple wallets before being parked in rsETH. The attacker did not swap the tokens into ETH on the main chain for further laundering, which ultimately proved to be a critical misstep.
This incident marks the largest Web3 hack of September so far. Total losses from exploits this month have already reached $326 million, surpassing the entire month of August, according to DeFi Llama.
How the Attack Unfolded
The exploit targeted a wallet holding leveraged rsETH within a Gnosis Safe. The wallet had authorized a whitelisted Safe module to act as a strategy executor for automating DeFi earnings.
That trusted module became the entry point. Because it was already whitelisted, a caller could exploit it without additional authorization. The vulnerability allowed the attacker to drain the funds in one swift move.
What happened next added an unusual twist. The Yoink MEV bot front-ran the exploiter in the same block, intercepting the ETH withdrawal from rsETH. The bot's destination address now holds only 44 ETH, while the remaining funds stay locked in rsETH.
Kelp DAO Responds with Emergency Freeze
Kelp DAO acted quickly after the attack. The protocol flagged the bot's destination address and placed a temporary 24-hour pause on all rsETH movement in and out of that address.
"Out of an abundance of caution, we've placed that address under a temporary 24-hour pause," Kelp DAO stated. "We're working closely with security experts to investigate and resolve this as quickly as possible."
The DAO confirmed its own vaults remained safe and avoided losses in this incident. However, the protocol also suspended deposits and withdrawals to prevent the attacker or the bot from moving funds out of the ecosystem.
This is not Kelp DAO's first brush with security breaches. The protocol previously lost $292 million in rsETH, which also impacted Aave vaults. Despite those challenges, Kelp DAO has managed to recover its total value locked to $1.06 billion after months of rebuilding.
Funds Frozen as Recovery Hangs in the Balance
As of September 15, rsETH traded at $2,663.68. The destination address remains blocked for 24 hours while Kelp DAO decides whether to pursue clawback measures.
The DAO has precedent for recovering stolen funds through governance votes. In the previous exploit, a community vote allowed some stolen assets to be reverted. Whether a similar approach will apply here remains unclear.
The role of the Yoink bot has drawn attention. In this case, the bot inadvertently acted as a white hat, salvaging funds before they could be bridged to ETH and laundered through a mixer. However, the bot's intervention does not guarantee the return of the rsETH.
Broader DeFi Security Concerns
September's exploit activity reflects a concerning trend. Over the past three months, attacks have accelerated from earlier lows, with growing interest in AI-assisted hacks targeting liquidity in DeFi protocols and specific vaults.
Most attacks have been under $1 million, but the Gnosis Safe wallet exploit stands out as the largest this month. The incident follows the Bitcoin Pay hacker, who stole 4,000 BTC from non-custodial user wallets.
As DeFi and lending recover, with more funds flowing into vaults, the risk of further Web3 attacks against vulnerable contracts may rise.
Coinasity's Take
The Gnosis Safe exploit highlights a persistent vulnerability in DeFi: trusted modules and whitelisted contracts can become attack vectors if not properly audited. Kelp DAO's swift freeze and the Yoink bot's inadvertent intervention bought valuable time, but the episode underscores that recovery often depends on luck as much as protocol design. Until security practices catch up with the pace of innovation, exploits like this will remain a feature of the DeFi landscape.
DISCLAIMER
This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments involve substantial risk and extreme volatility - never invest money you cannot afford to lose completely. The author may hold positions in the cryptocurrencies mentioned, which could bias the presented information. Always conduct your own research and consider consulting a qualified financial advisor before making any investment decisions.
About Arnas Bach
Blockchain Researcher & Developer | 8+ Years Crypto Market Experience
Seasoned cryptocurrency researcher and blockchain developer with deep expertise in protocol analysis, smart contract development, and market insights since 2017. Specializes in emerging blockchain technologies, DeFi ecosystems, and cryptocurrency market trends. Combines technical development skills with comprehensive market research to deliver actionable insights for the digital asset space.











