خبری درباره‌ی Safe (SAFE)

Kelp freeze thwarts rsETH theft as “Yoink” MEV bot captures $7.7M

CryptoBreaking ۱ ساعت پیش خلاصه‌ی فارسی · ۴۴۷ کلمه
Kelp freeze thwarts rsETH theft as “Yoink” MEV bot captures $7.7M

An attacker attempted to drain approximately $7.7 million worth of rsETH from an Ethereum Safe wallet by abusing a custom module tied to the wallet. Instead of successfully exiting with the funds, the operation was interrupted when an MEV bot captured the tokens first, according to blockchain security firm Blockaid. Blockaid said the exploit used a public “keeper” multicall to route a custom Uniswap v4 liquidity module into an attacker-controlled hooked pool. In that setup, aEthrsETH was unwrapped into rsETH—allowing the attacker to try to take custody of the extracted tokens. Key takeaways Blockaid traced the incident to a custom Uniswap v4 liquidity module connected to a Safe wallet. The attacker reportedly targeted rsETH holdings worth about $7.73 million, but an MEV bot intercepted the funds. On-chain activity indicates the MEV bot transferred rsETH out before the original exploiter could act. Kelp, the rsETH protocol, placed a 24-hour pause on the recipient address as a precaution while stating rsETH remains fully backed. Minting, withdrawals, and integrations were reported as continuing normally during the investigation. From Safe module to attacker-controlled liquidity pool In its report, Blockaid described a two-stage strategy. First, the attacker leveraged a Safe-related “keeper multicall” as a public execution path. Then, through that multicall, the attacker directed a custom Uniswap v4 liquidity module into a hooked pool created by the attacker. The key mechanics, per Blockaid, were centered on converting aEthrsETH into rsETH inside the attacker’s pool. This effectively created a route for extracting rsETH from the victim wallet using functionality already wired into the Safe. Blockaid identified the impacted wallet as belonging to an unidentified Safe user and estimated that roughly $7.73 million in rsETH was taken at the time of its initial reporting. MEV bot “Yoink” front-runs the exploiter Rather than letting the exploiter obtain control of the extracted rsETH, the transaction appears to have been front-run by an MEV bot named “Yoink.” MEV bots monitor mempool and transaction patterns to capture opportunities when transactions can be reordered for profit or advantage. Blockaid said Yoink took the rsETH before the original attacker could secure the funds. Etherscan transaction data linked in Blockaid’s update indicates that Yoink transferred about 18.93 ETH—valued at roughly $46,000 at the time—during the same transaction to an address labeled as a “block builder.” While this does not by itself clarify the bot’s full profit model, the pattern is consistent with MEV-style routing: the bot captures value in the reordered execution and settles or forwards funds through builder-related infrastructure. Kelp pauses a receiving address; contracts reportedly safe After the extraction and interception, the rsETH protocol behind Kelp moved to reduce the risk of further token movement from the implicated destination.

عنوان اصلی (انگلیسی): Kelp freeze thwarts rsETH theft as “Yoink” MEV bot captures $7.7M

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Safe

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.