A Safe account was drained of $7.73M through compromised Uniswap V4 hooks.
Security & Exploits ·
A Safe wallet holding rsETH was drained of approximately $7.73M in Ethereum through a compromised Uniswap V4 hooks mechanism. The exploit did not stem from a vulnerability in Safe's core protocol itself, but rather from module authorization abuse within the victim's account configuration. An attacker leveraged a custom Uniswap V4 liquidity provider module, executing transactions via a public keeper and helper contract that routed through the module's Permit2 and PositionManager integrations.
The attack mechanism involved the attacker depositing liquidity into a hooked V4 pool, with the malicious hook then unwrapping aEthrsETH tokens to rsETH and transferring the funds out of the Safe. The drain occurred in multiple transactions beginning at 04:38 UTC, with the largest extraction removing approximately $7.73M worth of 2,900 rsETH in a single transaction. Subsequent smaller withdrawals followed over the next hour, totaling additional losses.
The incident highlights a supply-chain risk in modular wallet architecture: while Safe's core authorization mechanisms remained intact, the third-party LP module's integration with Uniswap V4's hook system created an attack surface. It remains unclear how the attacker gained control over the hook logic or whether the module itself contained a vulnerability or was merely misconfigured by the victim.