Safe Wallet Modules After the rsETH Exploit: How to Check Permissions
A custom Safe module was involved in the September 15 rsETH incident. Safe users should understand and review enabled modules and delegated permissions.
Crypto Support & Research Desk

Direct answer: The September 15 rsETH incident is a reminder that a Safe can have enabled modules capable of executing transactions without the normal owner-signature flow. The incident was linked to a custom module rather than Safe core contracts, but Safe users should review every enabled module and remove permissions they no longer understand or need.
What happened?
Security reporting says a custom liquidity-provider module associated with a Safe wallet was abused through a public keeper multicall path, moving roughly 2,882 rsETH. An MEV bot reportedly front-ran the original attacker and captured the funds. The key customer-help lesson is permission scope: a multisig threshold does not protect an action that an already-authorized module is permitted to execute independently.
What is a Safe module?
A module is a smart contract that a Safe can authorize to execute specific transactions on its behalf. Modules are useful for automation, recurring operations and protocol integrations, but that flexibility means an unnecessary or poorly understood module can expand the wallet's attack surface.
How to review your Safe
Open Safe through the official interface and review enabled modules, apps and delegated permissions. For each module, identify why it exists, who maintains it, whether it is still used, and what actions it can execute. If a module is obsolete or unexplained, follow Safe's official process to disable it. Removal itself may require the normal multisig approvals and gas.
Do not panic-sign a revocation
Attackers often exploit security news with fake revoke pages. Do not connect your Safe to a link sent in a direct message. Verify the official domain and inspect the transaction simulation before owners approve a module change. A revocation transaction should not transfer assets to a stranger.
Sources
https://cryptoticker.io/en/safe-wallet-modules-check/
https://en.cryptonomist.ch/2026/09/15/ethereum-rseth-exploit-loss/
FAQ
Was Safe itself hacked?
Available reporting attributes the incident to a custom authorized module, not a compromise of Safe core contracts.
Can a module bypass multisig signatures?
An enabled module can be designed to execute transactions without collecting the usual owner threshold for each action.
Should I remove every module?
No. Review purpose and risk first, and follow official documentation for modules you no longer need.
Informational security content only; not investment advice. Verify technical details and remediation steps with Safe and the relevant protocol before signing transactions.
Regulatory & Financial Risk Disclosure
The opinions, research, and analysis expressed in this publication are solely for educational and informational purposes and do not constitute investment, financial, legal, or tax advice. Digital asset markets are speculative and volatile. Past performance does not indicate future results. Always perform independent due diligence.
About the Author
Crypto Support & Research Desk
Crypto Support Desk publishes practical, source-led guides to exchange, wallet, network and on-chain service changes. Information is checked against primary or reputable security sources and is not investment advice.