September 17, 2026

Anatomy of the rsETH hack: how $7.73M left a wallet in one transaction

On September 15, 2,900 rsETH (≈$7.73M) were drained from a Safe wallet on Ethereum. Safe, Aave, Uniswap and rsETH itself were not hacked. A custom automation module was — and that was enough.

What happened, step by step:

Why it worked: three mistakes stacked — a public entry point + caller-supplied parameters + delegatecall with no target allowlist. A module bypasses owner signatures by design, which makes it the most dangerous surface of any Safe.

How to prevent it: allowlist pools and hooks; never delegatecall into targets chosen by the caller; withdrawal limits and timelocks on new targets; least privilege for modules (an LP module has no business touching the Aave position); a separate audit for custom modules; monitoring with an automatic circuit breaker.

The practical takeaway for P2P and anyone accepting funds: the proceeds are already moving through the transfer graph and can reach an address that sends you an "ordinary" payment within hours. The exchange will see that link on your first withdrawal. Screen the counterparty before you accept.

🔗 Exploit transaction: https://etherscan.io/tx/0x0e7680b06cb8a6f86c149d9ba90d98e3d334e7b072dde03909d43fcfd98a8705 🔎 Check any address in 10 seconds: https://t.me/amlconsensus_bot?start=en

Screen your counterparty now

Consensus of sources · verdict across 35 chains · connection graph and full audit · PDF with QR verification

Open @amlconsensus_bot — 1 free check