MEV bot front-runs $7.8M rsETH exploit on Ethereum

An Ethereum MEV bot known as Yoink has front-run an attempted Safe wallet exploit involving 2,900 rsETH, worth about $7.8 million, and paid nearly 19 ETH to secure the first position in the block. Summary Yoink received 2,900 rsETH before the original exploit transaction reverted in the same Ethereum block. The bot transferred 2,882.37 rsETH to a separate address and routed 17.63 rsETH through Uniswap v4. BlockSec traced the exploit to weak authorization checks in an executor contract linked to a Safe module. Blockaid said a public keeper multicall let the attacker route funds through a malicious hook pool. Yoink MEV bot takes the first position PeckShield identified the incident as an approximately $7.81 million attack involving rsETH, a liquid restaking token associated with KelpDAO, after an MEV bot placed its transaction ahead of the suspected attacker. #PeckShieldAlert MEV bot yoink front-runs a ~$7.81M $rsETH exploit on Ethereum pic.twitter.com/vAJwsCOfsQ — PeckShield September 15, 2026 On-chain records cited by security researchers show that Yoink received 2,900 rsETH in Ethereum block 25980525. From the total, the transaction sent 2,882.37 rsETH to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. At the time the address was reviewed, its balance stood at 2,882.36740883 rsETH. No transfer from the address was described in the initial reports, and the available information did not identify its owner or establish whether the funds would be returned. You might also like: What is MEV? Maximal Extractable Value, the invisible tax on crypto The remaining 17.63 rsETH moved to the Uniswap v4 Pool Manager. According to the transaction path, the Pool Manager then sent 18.95 ETH to the Yoink contract, which forwarded 18.93 ETH to the block builder. Paying almost the full ETH amount to the builder left little direct ETH profit from that part of the transaction. The large payment instead appears to have served as the bot’s bid for priority placement, although the cited researchers did not publish a complete profit calculation covering the retained rsETH or other transaction costs. Both Yoink’s transaction and the original exploit attempt landed in block 25980525. Yoink appeared at the top of the block, while the original transaction ran later and reverted. Security researchers viewed the ordering and failed follow-up transaction as evidence that the bot had detected the attack and moved first. Such competition relies on maximal extractable value, or MEV, which comes from controlling the inclusion and ordering of transactions. A June 2026 crypto.news guide to MEV explained that searchers scan pending activity for profitable openings, assemble transaction bundles, and pay builders to place them in a chosen position. Safe module checks allowed the exploit path BlockSec attributed the underlying weakness to faulty authorization checks in an executor contract connected to an enabled Safe module.
عنوان اصلی (انگلیسی): MEV bot front-runs $7.8M rsETH exploit on Ethereum
مشاهدهی خبر کامل در منبع ↗ بازگشت به Safeاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.