Invest1 publisher2 min readPublished
September's biggest Web3 exploit accounts for 2.4% of the month's DeFi losses
A Gnosis Safe lost $7.73M in rsETH on September 15 through an automation module its own owner had whitelisted, an MEV bot took the proceeds in the same block, and Kelp DAO froze the destination address for 24 hours.
The Investor · Invest desk

What happened
- An unidentified Gnosis Safe wallet was drained in a single transaction on September 15, losing the equivalent of 2,153 ETH in rsETH that was then split across multiple wallets.
- The MEV bot Yoink front-ran the exploiter's withdrawal of ETH from rsETH and took the proceeds in the same block, leaving the loss stranded in rsETH rather than bridged ETH.
- Kelp DAO froze the deposited rsETH at the bot's destination address and suspended deposits and withdrawals to stop either party moving funds out of the ecosystem.
- Decentralized hacks and exploits for September to date have already passed the total for all of August.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Any Safe owner who has whitelisted an automation module as a strategy executor is reachable by whoever can call it, because the authorization was granted once and does not check the caller again.
- constraint Recovery here rests on a token issuer's ability to freeze an address and on an MEV operator's goodwill, neither of which is a contractual claim the wallet owner can enforce.
- decision An allocator sizing DeFi operational risk from headline exploits is pricing 2.4% of September and ignoring the rest, so the unit of measurement has to be incident frequency per protocol.
- contradiction The loss can be booked at $7.73M or at about $5.73M depending on which of the source's own figures is used, a $2M spread on a single transaction.
Take the single largest event out of DeFi Llama's September count and $318.3M is left, and because most of the month's recorded attacks came in under $1M each, reaching that remainder takes more than 318 separate incidents [2][13]. The $7.73M drained from one Gnosis Safe wallet is the biggest Web3 hack of the month to date and 2.4% of its total [13][1].
The owner had granted the entry point on purpose. The Safe held leveraged rsETH and had authorized a whitelisted Safe module as a strategy executor to automate DeFi earnings, and because the module was already whitelisted, a caller could use it without any further authorization [5]. Kelp DAO said all its vaults were safe [11].
The value stayed in rsETH on the main chain. The initial transaction shows the funds parked in rsETH without being swapped [4], and the 44 ETH sitting in the bot's destination address is about 2% of the 2,153 ETH the wallet lost [7][3][4]. Kelp DAO flagged that address. "Out of an abundance of caution, we've placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in or out of it," Kelp DAO said [9].
Two figures for this loss are in circulation. Blockaid put the loss at $7.73M [1]; 2,153 units at the $2,663.68 rsETH price quoted for September 15 come to about $5.73M, roughly $2M less [3][15][3]. The account leaves both numbers standing. An allocator has to choose which of the two it is underwriting.
Whether any of it comes back is a governance question, and Kelp DAO has been here before: after a $292M rsETH loss that also hit Aave vaults, a vote could revert some of the stolen funds [12][19]. This one is 0.73% of the $1.06B Kelp has recovered in value locked [17][5]. The pause runs 24 hours while a decision is made on clawing back the funds, and the report is explicit that the bot's activity does not guarantee the rsETH is returned [19][18].
I would expect a partial recovery through that same freeze-and-vote route, and I would expect October to look like September: a run of small losses with one visible outlier. The counter-thesis is that the size distribution is moving, since the same account has exploits accelerating over three months with more interest in AI-assisted attacks and in the liquidity accumulating in specific vaults [20]. Two other paths: the pause lapses without a vote and the rsETH moves, or Yoink's operator keeps the 44 ETH [7]. What would break the frequency read is a month where one exploit is a third of the total [1].
What to watch
- Whether the 24-hour pause is extended, allowed to lapse, or converted into a governance vote on clawing back the rsETH.
- Whether Yoink's operator returns the rsETH or moves the 44 ETH sitting in the flagged destination address.
- DeFi Llama's final September total, and whether the month stays composed mostly of sub-$1M events.