Approximately $7.8M drained from Safe wallet on Ethereum due to external contract vulnerability
On September 15, a Safe smart account on Ethereum suffered a $7.8 million exploit. Security firms Blockaid, BlockSec, and GoPlus Security identified the root cause as a flawed authentication process in an external execution contract, rather than a vulnerability in the Safe core contract, Aave, or rsETH. The attacker bypassed authentication by manipulating parameters, allowing them to execute transactions on behalf of the victim's Safe. However, an MEV bot named Yoink front-ran the attacker's transaction, successfully intercepting approximately 2,900 rsETH before the original attacker could secure the majority of the funds.
Summaries are written by AI from the original article. Not investment advice.