An unidentified Gnosis Safe wallet was drained for approximately $7.73 million in rsETH on September 15, 2026, in what has become the largest Web3 exploit of the month. According to Blockaid and DeFi Llama data, the attacker removed the equivalent of 2,153 ETH in a single transaction. The stolen funds were split and moved across multiple wallets, but notably remained parked as rsETH rather than being swapped into ETH on the main chain for immediate laundering.
Security researchers traced the breach to a flawed multicall(address, bytes[]) function in the Router contract, where an authorization check in the _isAuthorized function allowed a malicious caller to execute crafted call data. The compromised wallet had whitelisted a Safe module as a strategy executor for automated DeFi earnings; because the module was already trusted, the attacker could interact with it without additional authorization.
The situation became more complex when an MEV bot named Yoink front-ran the exploiter in the same block, intercepting the rsETH before it could be converted. Kelp DAO responded by placing the bot’s destination address under a temporary 24-hour pause and by suspending rsETH deposits and withdrawals as a precaution. Kelp DAO emphasized that its vaults remained safe and no protocol-level losses had occurred, though the address freeze prevents the attacker or bot from moving funds out of the ecosystem.
The incident underscores rising DeFi security risks. In September to date, decentralized hacks and exploits have already surpassed August levels, with roughly $326 million stolen across the ecosystem, according to DeFi Llama. Kelp DAO had previously suffered a much larger loss of about $292 million in rsETH, which also affected Aave vaults. As of September 15, rsETH traded at $2,663.68. Traders and analysts will now watch whether Kelp DAO initiates a governance vote to claw back the frozen funds and whether the exploit accelerates demand for stricter smart contract audits and enhanced DeFi security measures.