Safe wallet user loses $8M in Ethereum exploit, says Blockaid

Summary

An unidentified Safe wallet user has lost approximately $7.73 million worth of rsETH due to an exploit in Ethereum, as reported by Blockaid. The attack specifically targeted a custom liquidity provider module within Uniswap v4 using a public keeper multicall and routed funds into a hook pool created by the attacker. This incident highlights the security risks associated with Uniswap v4's hook mechanism, which, while intended for custom pool logic, has introduced new vulnerabilities that can be exploited without compromising private keys through the use of custom modules in smart wallets.

Tokens

$rsETH

Analysis

Blockaid: Blockaid is a blockchain security company focused on real-time threat detection and prevention for crypto transactions and wallets. It recently detected and reported on multiple exploits, including this Safe wallet incident as well as attacks on protocols like Rain and Symbiosis. Blockaid's monitoring services provide alerts to users and networks about malicious activities as they unfold. Safe wallet: Safe is a prominent smart contract wallet platform on Ethereum and other blockchains, specializing in multisignature accounts for secure asset management. It has recently launched features like Safenet Beta for enhanced security networks and is preparing Safe Pro for professional users. In this news, an unidentified user's Safe multisig wallet was targeted in an Ethereum exploit involving a custom Uniswap v4 liquidity provider module. DeFi Exploit Monitoring: Specialized security firms provide ongoing detection of sophisticated DeFi attacks involving wallet modules and liquidity protocols. Smart Wallet Module Risks: Custom modules authorized in smart wallets can create vulnerabilities when integrated with new protocol features like Uniswap v4 hooks, allowing exploitation via public calls without direct key compromise. Uniswap v4 Hooks Security: Uniswap v4's hook mechanism, while designed for custom liquidity pool logic, has introduced new attack surfaces through malicious or compromised hooks in DeFi interactions.

Categories

cryptoethereumdefitechripple

Related sources

View Original Tweet