An MEV bot called Yoink front-ran a transaction connected to an rsETH exploit targeting a Safe wallet on Ethereum on Tuesday. PeckShield described the incident as an approximately $7.81 million rsETH exploit.
Onchain fund movements
Onchain records show the Yoink transaction received 2,900 rsETH and sent 2,882.37 rsETH to 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. When checked, Etherscan showed a balance of exactly 2,882.36740883 rsETH at that address.
The same transaction also sent 17.63 rsETH to Uniswap’s v4 Pool Manager. The pool then sent 18.95 ETH to the Yoink contract, which forwarded 18.93 ETH to the block builder.
Transaction ordering in the same block
The Yoink transaction and the original attack transaction both landed in Ethereum block 25980525 at 12:38 a.m. ET. Yoink took position zero in the block, while the original attack transaction hit an execution revert.
That sequence matches security researchers’ conclusion that Yoink front-ran the attack transaction.
Researchers point to a module authorization flaw
BlockSec attributed the exploit to a flawed authorization check in an executor contract connected to an enabled Safe module. According to the firm, attacker-controlled calls could execute through the trusted executor.
Blockaid said the attacker used a public keeper multicall to route a custom Uniswap v4 liquidity module into an attacker-created hooked pool. The hook then unwrapped aEthrsETH into rsETH.
BlockSec also said the exploit moved about 2,900 aEthrsETH into a Uniswap v4 pool paired with a token called Permissionless Attacker Token, leaving the Safe with a liquidity-position NFT.
Blockaid identified the target as an unidentified user’s Safe that was using a custom module.
When checked, the address that received 2,882.37 rsETH in the Yoink transaction showed a balance of 2,882.36740883 rsETH.

