Uniswap v4 Hook Exploit Drains $7.73M in rsETH From User's Safe Wallet

AI Market Summary
Blockaid reports a $7.73M rsETH loss after a Safe wallet's custom Uniswap V4 LP module was redirected via a public Keeper Multicall to an attacker-controlled Hook Pool, enabling malicious unwrapping and same-block MEV extraction. The incident highlights v4 hook/module integration and permissioning risks, potentially tightening risk appetite for DeFi LP automation and increasing scrutiny of hook-enabled pool interactions on Ethereum.
Impact level
● Medium
Affected assets
UNI/USDT+5.13%
AI Insight · UNI/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ME News reported that on Sept. 15 (UTC+8), Blockaid monitoring showed an unidentified user's Safe wallet on Ethereum was compromised, with confirmed losses of about $7.73 million in rsETH. The attacker allegedly abused a public Keeper Multicall to reroute the Safe's custom Uniswap v4 LP module to an attacker-created Hook Pool. A malicious Hook was then used to unwrap aEthrsETH into rsETH, after which the assets were extracted by Yoink MEV within the same block. (Source: BlockBeats)