Crypto News

Bot Named Yoink Hijacks $7.8 Million Crypto Heist From Vulnerable Wallet

Sep 16, 2026 12:30 ethereum hack gnosis rseth security
Bot Named Yoink Hijacks $7.8 Million Crypto Heist From Vulnerable Wallet

Automated Bot Foils $7.8 Million Ethereum Heist

An automated trading bot called "yoink" intercepted a $7.8 million cryptocurrency heist on the Ethereum blockchain. The incident involved an attacker draining about 2,900 rsETH, a token issued by Kelp DAO, from a Gnosis Safe wallet, which is a popular platform for secure crypto storage. The bot front-ran the attack transaction to seize the funds before the original attacker could complete the theft.

Security firms traced the loss to a coding mistake in a helper contract that the wallet owner had authorized. The error allowed anyone who named the helper contract as the target to gain approval, leading to unauthorized access.

Key Points from the Incident

  • The attacker removed approximately 2,900 rsETH, valued at roughly $7.8 million, from the wallet.
  • The bot yoink paid about $47,000 to prioritize its transaction and extract the tokens.
  • The vulnerability was in a helper contract, not in the core Gnosis Safe contracts.
  • Security firms BlockSec, Blockaid, and SlowMist confirmed the flaw.

Kelp DAO's Response to the Hack

Kelp DAO, which issues rsETH, stated that it detected suspicious activity on the address that received the stolen rsETH. As a precaution, it placed a 24-hour pause on the address, preventing rsETH from moving in or out during that period to investigate.

Security Firms Identify the Root Cause

Security analysis by BlockSec, Blockaid, and SlowMist found that the root cause was a flawed authorization check in the helper contract. The contract was designed to verify caller permission but incorrectly approved any caller that named the helper itself as the target.

AstraSec also noted that the failure was in the Multicall contract chosen by the wallet owner, emphasizing that Safe's core technology was not compromised.

What Is Confirmed About the Attack

It is confirmed that the theft occurred on Ethereum, involving about 2,900 rsETH valued at $7.8 million. The bot yoink successfully front-ran the attack transaction by paying a fee of approximately $47,000. The vulnerability was in the helper contract authorized by the wallet owner, leading to the movement of funds without proper permission.

What Remains Unclear

The identity of the original attacker is not disclosed in the sources. Additionally, the exact current status of the funds after the bot's intervention is not detailed, though it is known that the bot sent 2,882 rsETH to a separate address.

Why This Hack Matters for Crypto Users

This incident highlights risks in automated trading setups and the importance of secure coding in cryptocurrency wallets. It demonstrates how a simple mistake in a helper contract can lead to significant losses, even when using established platforms like Gnosis Safe.

Next Steps in the Investigation

Kelp DAO has implemented a 24-hour pause on the affected address to assess the situation and prevent further movement of the compromised rsETH. This temporary measure allows for investigation while safeguarding the remaining assets.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!