MEV Bot Yoink Stops $7.8M Ethereum rsETH Exploit in Its Tracks

Key Highlights A hacker attempted to drain $7.8 million worth of rsETH from an Ethereum Safe wallet through a vulnerability in a custom Uniswap v4 module An MEV bot named “Yoink” successfully front-ran the malicious transaction, securing the funds ahead of the would-be exploiter The bot paid approximately 19 ETH to a block builder to guarantee first position in the transaction block KelpDAO, rsETH’s issuing protocol, imposed a 24-hour freeze on the destination address as a security measure Security firm BlockSec identified the issue as insufficient authorization verification in an executor contract associated with a Safe module A sophisticated MEV bot operating under the name Yoink successfully thwarted a $7.8 million attempted heist of rsETH tokens on the Ethereum network, securing the digital assets before the malicious actor could complete the theft. #PeckShieldAlert MEV bot yoink front-runs a ~$7.81M $rsETH exploit on Ethereum pic.twitter.com/vAJwsCOfsQ — PeckShield September 15, 2026 The attempted exploit occurred on September 15, 2026, within Ethereum block number 25980525. An unidentified threat actor sought to leverage a vulnerability in a customized module integrated with a Safe smart contract wallet. Blockchain security company Blockaid reported that the hacker utilized a publicly accessible keeper multicall function to redirect assets through a compromised Uniswap v4 hook pool. The strategy involved converting aEthrsETH tokens into rsETH, KelpDAO’s liquid restaking token. However, the attacker’s plan failed completely. Yoink, an automated program designed to identify and capitalize on profitable blockchain transaction opportunities, spotted the exploitation attempt and executed a front-running transaction. The Mechanics Behind Yoink’s Successful Intervention The Yoink bot secured 2,900 rsETH tokens at the beginning of the block. It subsequently transferred 2,882.37 rsETH to a different wallet address while directing the remaining 17.63 rsETH through the Uniswap v4 protocol. WILD: Ethereum MEV bot “Yoink” FRONT-RUNS a hacker’s $7.8 MILLION exploit and steals the entire loot. A hacker attacked an Ethereum whale’s Gnosis Safe wallet using a custom Uniswap V4 hook to unwrap aETHrsETH into freely transferable rsETH. But once the exploit hit the… pic.twitter.com/Pqi7eY7BJb — Coin Bureau (@coinbureau) September 16, 2026 The Pool Manager contract then returned approximately 18.95 ETH to Yoink’s contract address. The bot immediately forwarded 18.93 ETH to a block builder—this substantial payment functioned as Yoink’s competitive bid to secure priority transaction ordering within the block. The hacker’s original exploitation attempt executed later in the identical block but failed and reverted. Cybersecurity analysts indicate that the transaction sequence demonstrates Yoink identified the attack vector and executed its countermeasure first. BlockSec’s investigation revealed that inadequate authorization verification in an executor contract connected to the Safe wallet module was the underlying vulnerability. This security gap permitted external calls to pass through a pathway the wallet incorrectly treated as trustworthy.
عنوان اصلی (انگلیسی): MEV Bot Yoink Stops $7.8M Ethereum rsETH Exploit in Its Tracks
مشاهدهی خبر کامل در منبع ↗ بازگشت به یونیسواپاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.