Close Menu

    Subscribe to Updates

    What's Hot

    MEV bot front-runs $7.8M rsETH exploit on Ethereum

    September 15, 2026

    Allocation Update – Q4 2024

    September 15, 2026

    Chainlink price nears breakout as Bollinger Bands narrow

    September 15, 2026
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home MEV bot front-runs $7.8M rsETH exploit on Ethereum
    Crypto

    MEV bot front-runs $7.8M rsETH exploit on Ethereum

    John SmithBy John SmithSeptember 15, 2026No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    An Ethereum MEV bot known as Yoink has front-run an attempted Safe wallet exploit involving 2,900 rsETH, worth about $7.8 million, and paid nearly 19 ETH to secure the first position in the block.

    Summary

    • Yoink received 2,900 rsETH before the original exploit transaction reverted in the same Ethereum block.
    • The bot transferred 2,882.37 rsETH to a separate address and routed 17.63 rsETH through Uniswap v4.
    • BlockSec traced the exploit to weak authorization checks in an executor contract linked to a Safe module.
    • Blockaid said a public keeper multicall let the attacker route funds through a malicious hook pool.

    Yoink MEV bot takes the first position

    PeckShield identified the incident as an approximately $7.81 million attack involving rsETH, a liquid restaking token associated with KelpDAO, after an MEV bot placed its transaction ahead of the suspected attacker.

    On-chain records cited by security researchers show that Yoink received 2,900 rsETH in Ethereum block 25980525. From the total, the transaction sent 2,882.37 rsETH to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0.

    At the time the address was reviewed, its balance stood at 2,882.36740883 rsETH. No transfer from the address was described in the initial reports, and the available information did not identify its owner or establish whether the funds would be returned.

    The remaining 17.63 rsETH moved to the Uniswap v4 Pool Manager. According to the transaction path, the Pool Manager then sent 18.95 ETH to the Yoink contract, which forwarded 18.93 ETH to the block builder.

    Paying almost the full ETH amount to the builder left little direct ETH profit from that part of the transaction. The large payment instead appears to have served as the bot’s bid for priority placement, although the cited researchers did not publish a complete profit calculation covering the retained rsETH or other transaction costs.

    Both Yoink’s transaction and the original exploit attempt landed in block 25980525. Yoink appeared at the top of the block, while the original transaction ran later and reverted. Security researchers viewed the ordering and failed follow-up transaction as evidence that the bot had detected the attack and moved first.

    Such competition relies on maximal extractable value, or MEV, which comes from controlling the inclusion and ordering of transactions. A June 2026 crypto.news guide to MEV explained that searchers scan pending activity for profitable openings, assemble transaction bundles, and pay builders to place them in a chosen position.

    Safe module checks allowed the exploit path

    BlockSec attributed the underlying weakness to faulty authorization checks in an executor contract connected to an enabled Safe module. Under the firm’s account, attacker-controlled calls could pass through an executor that the wallet treated as trusted.

    Safe is a smart contract wallet system that can require several signers to approve transactions. Its module framework also lets account owners add contracts that can perform specific actions under predefined rules, reducing the need for manual signatures on every operation.

    An enabled module therefore becomes part of the wallet’s security boundary. BlockSec’s analysis indicates that the affected executor failed to confirm the authority behind a call correctly, allowing an outside party to reach functions through a trusted route.

    The report describes a problem in the executor contract associated with the wallet configuration rather than a flaw in Ethereum’s consensus system. Available details also do not show that the core Safe contracts were compromised, so attributing the incident to the entire Safe platform would go beyond the security firms’ findings.

    Blockaid provided a more detailed account of how the attacker tried to use the permission failure. According to the security company, the attacker accessed a public keeper multicall and directed a custom Uniswap v4 liquidity module toward a hook pool under the attacker’s control.

    Uniswap v4 hooks are contracts that can run custom instructions at set points in a pool’s operations. Blockaid said the maliciously created hook pool was then used to unpack aEthrsETH into rsETH, producing the tokens targeted in the transaction.

    Combining a public keeper function with a trusted execution route allowed the call to reach the custom liquidity setup, according to Blockaid’s analysis. Yoink’s bot saw the opportunity before the attacker completed it and submitted a competing transaction that captured the same output.

    No statement included in the supplied reports identifies the suspected attacker, the Yoink operator or the block builder. The reports also did not say whether a recovery agreement, bounty negotiation or legal process had begun.

    The rsETH transaction adds to 2026 DeFi losses

    The attempted extraction occurred during a year of heavy losses across decentralized finance. A September report on DeFi security losses cited CertiK and Forbes estimates showing that protocols lost at least $1.3 billion to exploits during the first eight months of 2026.

    The report found that compromised credentials and privileged access had overtaken traditional smart contract faults as the main source of losses by value. The Yoink incident differs in its reported mechanics because BlockSec traced the opening to authorization logic within an executor linked to a Safe module.

    rsETH has also appeared in a separate major security event this year. In April, an attacker minted 116,500 unbacked rsETH after compromising infrastructure tied to a LayerZero verifier, according to the previous coverage. The attacker then used the tokens as collateral on Aave to borrow other assets.

    Security researchers have not connected the April incident to the transaction in block 25980525. The two events involved different reported weaknesses, and the latest case concerned an attempted movement of 2,900 existing rsETH through a wallet execution path.

    U.S. authorities have treated some MEV schemes as fraud

    For U.S. users, the Yoink transaction also shows why the term “front-running” does not by itself settle the legal status of an on-chain trade. Federal authorities have pursued certain MEV operations when prosecutors alleged that their operators used deception or tampered with systems to obtain funds.

    In May 2024, the U.S. Department of Justice charged two brothers over an alleged Ethereum scheme that obtained about $25 million in cryptocurrency within roughly 12 seconds. Prosecutors alleged that Anton and James Peraire-Bueno manipulated the process Ethereum traders used to order transactions and fraudulently gained access to pending private transactions.

    The Justice Department charged the brothers with conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. Its allegations concerned the methods allegedly used to obtain the trading information and manipulate the process, rather than treating every transaction-ordering strategy as automatically criminal.

    No U.S. regulator or law-enforcement agency has announced an action involving Yoink or the attempted rsETH exploit based on the information supplied. The cited blockchain security firms have limited their findings to transaction ordering, the Safe-linked executor’s authorization checks, and the Uniswap v4 hook route used to unpack aEthrsETH.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    Chainlink price nears breakout as Bollinger Bands narrow

    September 15, 2026

    Ethereum price loses $2,500 as MACD turns bearish

    September 15, 2026

    Poland faces $378M loss case over failed Venezuela oil deal

    September 15, 2026
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    MEV bot front-runs $7.8M rsETH exploit on Ethereum

    By John SmithSeptember 15, 20260

    An Ethereum MEV bot known as Yoink has front-run an attempted Safe wallet exploit involving…

    Allocation Update – Q4 2024

    September 15, 2026

    Chainlink price nears breakout as Bollinger Bands narrow

    September 15, 2026

    Pectra Testnet Announcement | Ethereum Foundation Blog

    September 15, 2026

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (22)
    • Bitcoin (11)
    • Blockchain (14)
    • Crypto (714)
    • Ethereum (451)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.