A security bot snatched most of a $7.8 million crypto theft in the same block the hacker tried to cash out, and Kelp DAO has locked the address holding the loot for 24 hours.
The incident began on September 15, when an attacker exploited a flawed authorization check in a helper Multicall contract to drain roughly 2,900 rsETH, about $7.8 million, from a Gnosis Safe wallet on Ethereum. Blockaid and SlowMist put the confirmed loss nearer $7.73 million on-chain; BlockSec Phalcon and AstraSec give the rounded figure. The flaw was not in Gnosis Safe’s core contracts or in Kelp’s contracts. The helper contract the wallet owner had authorized approved any caller that named itself as the target, letting attacker-crafted calls execute through an enabled Safe module.
The hacker then moved the tokens into a Uniswap V4 pool created minutes earlier, paired with a worthless token called Permissionless Attacker Token, to convert the stash. That plan failed in the same block: an MEV bot called yoink saw the attack transaction in the public mempool, paid roughly $47,000 in priority fees to jump the queue, and captured about 2,882 rsETH before the attacker could act. The bot routed the funds to an address it controls, and the Safe was left holding a worthless liquidity receipt. The roughly $47,000 priority fee is a reported figure, not an on-chain confirmed one; the front-run itself is confirmed by BlockSec Phalcon, Blockaid and SlowMist.
Kelp DAO, which issues rsETH, said on X that it had detected suspicious activity on the address that received the tokens. “Out of an abundance of caution, we’ve placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in or out of it,” the protocol said in the announcement.
The pause is a wallet-level measure, Kelp DAO said, adding that its contracts are safe, rsETH remains fully backed, and minting and withdrawals are running normally. That is the issuer’s own assessment, not an independent one. The pause expires around September 16, after which the funds in the bot’s address can move again.
Neither the attacker nor the owner of the drained wallet has been identified. Kelp DAO said a full update will follow once its review concludes.


