MEV Bot Yoink Front-Runs $7.81 Million rsETH Exploit Targeting Safe Wallet on Ethereum

MEV Bot Yoink Front-Runs $7.81 Million rsETH Exploit Targeting Safe Wallet on Ethereum

N
News Editor
2026-09-15 16:03:32
An MEV bot known as Yoink front-ran a transaction tied to an rsETH exploit targeting a Safe wallet on Ethereum, in an incident PeckShield valued at roughly $7.81 million. Onchain data shows the Yoink transaction received 2,900 rsETH, sent 2,882.37 rsETH to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, and routed 17.63 rsETH to Uniswap v4’s Pool Manager. The pool then sent 18.95 ETH to the Yoink contract, which forwarded 18.93 ETH to the block builder. Both the Yoink transaction and the original attack transaction were included in Ethereum block 25980525 at 12:38 a.m. ET. Yoink landed in position zero, while the original attack reverted. Security researchers said that ordering matches a front-running pattern. BlockSec linked the exploit to a flawed authorization check in an executor contract tied to an enabled Safe module, while Blockaid said the attacker used a public keeper multicall to direct a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where aEthrsETH was unwrapped into rsETH.

An MEV bot called Yoink front-ran a transaction connected to an rsETH exploit targeting a Safe wallet on Ethereum on Tuesday. PeckShield described the incident as an approximately $7.81 million rsETH exploit.

Onchain fund movements

Onchain records show the Yoink transaction received 2,900 rsETH and sent 2,882.37 rsETH to 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. When checked, Etherscan showed a balance of exactly 2,882.36740883 rsETH at that address.

The same transaction also sent 17.63 rsETH to Uniswap’s v4 Pool Manager. The pool then sent 18.95 ETH to the Yoink contract, which forwarded 18.93 ETH to the block builder.

Transaction ordering in the same block

The Yoink transaction and the original attack transaction both landed in Ethereum block 25980525 at 12:38 a.m. ET. Yoink took position zero in the block, while the original attack transaction hit an execution revert.

That sequence matches security researchers’ conclusion that Yoink front-ran the attack transaction.

Researchers point to a module authorization flaw

BlockSec attributed the exploit to a flawed authorization check in an executor contract connected to an enabled Safe module. According to the firm, attacker-controlled calls could execute through the trusted executor.

Blockaid said the attacker used a public keeper multicall to route a custom Uniswap v4 liquidity module into an attacker-created hooked pool. The hook then unwrapped aEthrsETH into rsETH.

BlockSec also said the exploit moved about 2,900 aEthrsETH into a Uniswap v4 pool paired with a token called Permissionless Attacker Token, leaving the Safe with a liquidity-position NFT.

Blockaid identified the target as an unidentified user’s Safe that was using a custom module.

When checked, the address that received 2,882.37 rsETH in the Yoink transaction showed a balance of 2,882.36740883 rsETH.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
8700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.