Kelp DAO suspends deposits and withdrawals as Gnosis wallet suffers $7.8M exploit

An unidentified Gnosis Safe wallet was exploited for nearly $7.8M in rsETH. The attack drained DeFi liquidity, leaving the token and vaults with worthless tokens. An attack was registered on September 15 against a Gnosis Safe wallet user, who has not yet been identified. The wallet was exploited for $7.73M in rsETH, according to Blockaid data. The wallet was drained in a single transaction, taking away the equivalent of 2,153 ETH, which was later split and moved across multiple wallets. The initial transaction shows the funds were finally parked in rsETH, without being swapped into ETH on the main chain for further laundering. This is the next major hack after the Bitcoin Pay hacker took 4,000 BTC from non-custodial user wallets. For September to date, decentralized hacks and exploits already surpass the level for the whole of August. In the past three months, exploits have accelerated from their lows, showing more interest in AI-assisted hacks and targeting liquidity accumulation in DeFi protocols and specific vaults. Web3 hacks accelerated in September, already surpassing the levels from August. The recent exploit is the largest Web3 hack for the month. | Source: DeFi Llama In September to date, a total of $326M was hacked, according to DeFi Llama data. Most of the attacks and exploits were under $1M, making the recent wallet exploit the biggest Web3 hack for September to date. How was the Gnosis wallet hacked? The recent exploit involved a wrapped form of rsETH, which was then transformed into ETH and moved on-chain. The series of transactions showed the initial attacker and the MEV bot completed the transfers in a single block. The initial attacker moved rsETH out of the wallet’s vault, but the MEV bot Yoink took all the rsETH, ending up in one destination address. | Source: Etherscan The initial wallet held leveraged rsETH in a Gnosis Safe, which authorized a whitelisted Safe module as a strategy executor to automate DeFi earnings. The trusted module turned out to be the entry point of the attack. A caller could exploit the Safe module with no extra authorization, since it was already whitelisted. What makes the attack even more complex is that the MEV bot Yoink front-ran the exploiter and took the ETH in the same block. The bot front-ran the withdrawal of ETH from rsETH, where the funds still remain in the form of rsETH. The bot’s destination address now contains only 44 ETH. Are other protocols affected by the exploit? The bot’s destination address was flagged by Kelp DAO, leading to a freeze of all the deposited rsETH. KelpDAO announced the address would be frozen as a precaution to prevent further losses. Out of an abundance of caution, we’ve placed that address under a temporary 24-hour pause.
عنوان اصلی (انگلیسی): Kelp DAO suspends deposits and withdrawals as Gnosis wallet suffers $7.8M exploit
مشاهدهی خبر کامل در منبع ↗ بازگشت به گنوسیساین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.