Crypto News

MEV bot Yoink front-runs $7.8 million rsETH exploit on Ethereum

Sep 17, 2026 08:56 ethereum mev rseth safe wallet uniswap
MEV bot Yoink front-runs $7.8 million rsETH exploit on Ethereum

Yoink bot jumps ahead of a Safe wallet exploit

An automated program known as the Yoink MEV bot slipped ahead of a hacker on Tuesday and took about $7.81 million worth of the token rsETH, according to blockchain security firm PeckShield, which described the incident as an approximately $7.81 million rsETH exploit.

The attempted theft targeted a Safe wallet, a type of smart-contract wallet often used by institutions, on the Ethereum network. MEV bots are automated traders that pay block builders to place their transactions early in a block, a practice known as front-running.

Both the Yoink transaction and the original attack transaction landed in Ethereum block 25980525 at 12:38 a.m. ET. Yoink's transaction held position zero in the block, while the attacker's transaction failed with an execution revert. That ordering matches what security researchers found: Yoink beat the attack into the block.

Key numbers

  • PeckShield put the exploit at roughly $7.81 million in rsETH.
  • Onchain records show the Yoink transaction received 2,900 rsETH and sent 2,882.37 rsETH to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, which held exactly 2,882.36740883 rsETH when checked.
  • The same transaction sent 17.63 rsETH to Uniswap's v4 Pool Manager. That pool returned 18.95 ETH to the Yoink contract, which then forwarded 18.93 ETH to the block builder.
  • The original attack transaction and the Yoink transaction were both included in block 25980525 at 12:38 a.m. ET on Tuesday.

What security researchers found

BlockSec attributed the exploit to a flawed authorization check in an executor contract connected to an enabled Safe module. The firm said attacker-controlled calls could execute through the trusted executor.

Blockaid said the attacker used a public keeper multicall to steer a custom Uniswap v4 liquidity module into an attacker-created hooked pool. The hook then unwrapped aEthrsETH into rsETH.

BlockSec said the exploit moved about 2,900 aEthrsETH into a Uniswap v4 pool paired with a token called Permissionless Attacker Token, leaving the Safe with a liquidity-position NFT. According to Blockaid, the target was an unidentified user's Safe using a custom module.

What is confirmed

Public Ethereum records confirm the Yoink transaction, its position as the first transaction in block 25980525, the 2,882.37 rsETH transfer, the 17.63 rsETH and 18.95 ETH movements, and the revert of the original attack transaction. The roughly $7.81 million figure comes from PeckShield's assessment rather than from a final accounting.

What is still unclear

The sources do not identify who controls the attacking address, who operates the Yoink bot, or who owns the Safe wallet that was targeted. They also do not say whether the Safe owner can recover any value, or whether the 2,882.37 rsETH will stay at the receiving address. PeckShield's dollar estimate remains a security firm's assessment, not a settled total.

Why this matters

The case shows how MEV bots, which normally profit by reordering or copying transactions, can in effect intercept the proceeds of an exploit before the attacker gets paid. It also highlights the risks of attaching custom third-party modules to Safe wallets, since the attack relied on a flawed authorization check inside an executor contract linked to an enabled module.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!