A roughly $7.8 million theft from a Gnosis Safe wallet on Ethereum has been traced to a helper contract the wallet owner had previously authorized, according to security firms reviewing the incident. The loss involved about 2,900 rsETH and, the firms said, did not stem from a flaw in Safe’s core contracts.
Researchers at SlowMist, BlockSec and AstraSec said the attacker abused a faulty permission check inside a Multicall-style helper contract. An automated bot known as “yoink” then front-ran the attacker’s transaction, paying about $47,000 to get ahead and ultimately capturing the tokens.
How the wallet was compromised
The wallet had been configured to let a helper contract move assets on its behalf, a setup commonly used by traders and other users who automate transactions. According to SlowMist and BlockSec, the helper contract was supposed to confirm that a caller was authorized before allowing funds to move.
Instead, the contract’s logic accepted any caller that specified the helper contract itself as the target. That mistake effectively opened the door for an attacker to use the approved helper to pull funds from the wallet. AstraSec described the issue as a flawed authorization check in the Multicall contract.
What happened to the rsETH
After gaining access, the attacker moved about 2,900 rsETH from the wallet. The tokens were then dumped into a trading pool that had been created only minutes earlier and paired rsETH against a token called Permissionless Attacker Token, which the reports described as worthless.
As a result, the wallet was left holding a receipt token with no meaningful value. Security researchers said the maneuver was part of the extraction path used in the theft.
Yoink bot front-ran the attack
The stolen assets did not remain with the original attacker for long. SlowMist and BlockSec said an automated bot known as “yoink” front-ran the exploit transaction by paying roughly $47,000 to jump ahead in transaction ordering.
The bot ended up taking the tokens and sent 2,882 rsETH to another address, according to the firms’ tracing. That added a second layer of complexity to the incident, with the exploit and the eventual capture of the assets involving different on-chain actors.
What firms and issuers said next
Multiple security firms said the problem was not in Safe itself but in a component the wallet owner had chosen to trust. Their analysis points to the authorized helper contract, rather than the wallet software’s core contracts, as the source of the failure.
Kelp DAO, the issuer of rsETH, said its own contracts remain secure and that rsETH is fully collateralized. The project also said it had detected potentially suspicious activity involving an address that received rsETH and placed that address under a temporary 24-hour pause, preventing rsETH from moving in or out during that period.
Source: www.coindesk.com