• CONTACT
  • MARKETCAP
Coin  Deskk
  • BOOKMARKS
  • What’s New
  • Cryptocurrency
  • Pages
    • Contact Us
    • Search Page
    • Customize Interests
    • My Bookmarks
  • Home Coin
  • Home Coin
Reading: MEV bot front-runs $7.8M rsETH exploit on Ethereum
Share
Coin  DeskkCoin  Deskk
Font ResizerAa
  • Home
  • Crypto
  • Market
  • Blockchain
  • Contact
Search
© 2026 Coindeskk News Network. All Rights Reserved.
What's New

MEV bot front-runs $7.8M rsETH exploit on Ethereum

Crypto
Last updated: September 15, 2026 5:09 pm
Crypto
Published: September 15, 2026
Share
MEV bot front-runs $7.8M rsETH exploit on Ethereum

An Ethereum MEV bot known as Yoink has front-run an attempted Safe wallet exploit involving 2,900 rsETH, worth about $7.8 million, and paid nearly 19 ETH to secure the first position in the block. Summary Yoink received 2,900 rsETH before the original exploit transaction reverted in the same Ethereum block. The bot transferred 2,882.37 rsETH to a separate address and routed 17.63 rsETH through Uniswap v4. BlockSec traced the exploit to weak authorization checks in an executor contract linked to a Safe module. Blockaid said a public keeper multicall let the attacker route funds through a malicious hook pool. Yoink MEV bot takes the first position PeckShield identified the incident as an approximately $7.81 million attack involving rsETH, a liquid restaking token associated with KelpDAO, after an MEV bot placed its transaction ahead of the suspected attacker. On-chain records cited by security researchers show that Yoink received 2,900 rsETH in Ethereum block 25980525. From the total, the transaction sent 2,882.37 rsETH to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. At the time the address was reviewed, its balance stood at 2,882.36740883 rsETH. No transfer from the address was described in the initial reports, and the available information did not identify its owner or establish whether the funds would be returned. The remaining 17.63 rsETH moved to the Uniswap v4 Pool Manager. According to the transaction path, the Pool Manager then sent 18.95 ETH to the Yoink contract, which forwarded 18.93 ETH to the block builder. Paying almost the full ETH amount to the builder left little direct ETH profit from that part of the transaction. The large payment instead appears to have served as the bot’s bid for priority placement, although the cited researchers did not publish a complete profit calculation covering the retained rsETH or other transaction costs. Both Yoink’s transaction and the original exploit attempt landed in block 25980525. Yoink appeared at the top of the block, while the original transaction ran later and reverted. Security researchers viewed the ordering and failed follow-up transaction as evidence that the bot had detected the attack and moved first. Such competition relies on maximal extractable value, or MEV, which comes from controlling the inclusion and ordering of transactions. A June 2026 crypto.news guide to MEV explained that searchers scan pending activity for profitable openings, assemble transaction bundles, and pay builders to place them in a chosen position. Safe module checks allowed the exploit path BlockSec attributed the underlying weakness to faulty authorization checks in an executor contract connected to an enabled Safe module. Under the firm’s account, attacker-controlled calls could pass through an executor that the wallet treated as trusted. Safe is a smart contract wallet system that can require several signers to approve transactions. Its module framework also lets account owners add contracts that can perform specific actions under predefined rules, reducing the need for manual signatures on every operation. An enabled module therefore becomes part of the wallet’s security boundary. BlockSec’s analysis indicates that the affected executor failed to confirm the authority behind a call correctly, allowing an outside party to reach functions through a trusted route. The report describes a problem in the executor contract associated with the wallet configuration rather than a flaw in Ethereum’s consensus system. Available details also do not show that the core Safe contracts were compromised, so attributing the incident to the entire Safe platform would go beyond the security firms’ findings. Blockaid provided a more detailed account of how the attacker tried to use the permission failure. According to the security company, the attacker accessed a public keeper multicall and directed a custom Uniswap v4 liquidity module toward a hook pool under the attacker’s control. Uniswap v4 hooks are contracts that can run custom instructions at set points in a pool’s operations. Blockaid said the maliciously created hook pool was then used to unpack aEthrsETH into rsETH, producing the tokens targeted in the transaction. Combining a public keeper function with a trusted execution route allowed the call to reach the custom liquidity setup, according to Blockaid’s analysis. Yoink’s bot saw the opportunity before the attacker completed it and submitted a competing transaction that captured the same output. No statement included in the supplied reports identifies the suspected attacker, the Yoink operator or the block builder. The reports also did not say whether a recovery agreement, bounty negotiation or legal process had begun. The rsETH transaction adds to 2026 DeFi losses The attempted extraction occurred during a year of heavy losses across decentralized finance. A September report on DeFi security losses cited CertiK and Forbes estimates showing that protocols lost at least $1.3 billion to exploits during the first eight months of 2026. The report found that compromised credentials and privileged access had overtaken traditional smart contract faults as the main source of losses by value. The Yoink incident differs in its reported mechanics because BlockSec traced the opening to authorization logic within an executor linked to a Safe module. rsETH has also appeared in a separate major security event this year. In April, an attacker minted 116,500 unbacked rsETH after compromising infrastructure tied to a LayerZero verifier, according to the previous coverage. The attacker then used the tokens as collateral on Aave to borrow other assets. Security researchers have not connected the April incident to the transaction in block 25980525. The two events involved different reported weaknesses, and the latest case concerned an attempted movement of 2,900 existing rsETH through a wallet execution path. U.S. authorities have treated some MEV schemes as fraud For U.S. users, the Yoink transaction also shows why the term “front-running” does not by itself settle the legal status of an on-chain trade. Federal authorities have pursued certain MEV operations when prosecutors alleged that their operators used deception or tampered with systems to obtain funds. In May 2024, the U.S. Department of Justice charged two brothers over an alleged Ethereum scheme that obtained about $25 million in cryptocurrency within roughly 12 seconds. Prosecutors alleged that Anton and James Peraire-Bueno manipulated the process Ethereum traders used to order transactions and fraudulently gained access to pending private transactions. The Justice Department charged the brothers with conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. Its allegations concerned the methods allegedly used to obtain the trading information and manipulate the process, rather than treating every transaction-ordering strategy as automatically criminal. No U.S. regulator or law-enforcement agency has announced an action involving Yoink or the attempted rsETH exploit based on the information supplied. The cited blockchain security firms have limited their findings to transaction ordering, the Safe-linked executor’s authorization checks, and the Uniswap v4 hook route used to unpack aEthrsETH.

Strategy Invests $2.57 Billion in Bitcoin as AJC Mining Launches New Bitcoin Cloud Mining Contracts
French police bust $1.8M crypto villa scam targeting wealthy couple
Will XRP price rebound as Brad Garlinghouse predicts $10 trillion flowing to XRPL?
ADA’s Crucial Moment: 2% Dip Near Key Support Level Sparks Curiosity
Cronos Unleashes DeFi Revolution with Crypto.com, Morpho Partnership

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Coinbase CEO says tokenized stocks should hold real securities Coinbase CEO says tokenized stocks should hold real securities
Next Article Arbitrum price jumps 8.8% as $0.155 test looms Arbitrum price jumps 8.8% as $0.155 test looms

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
Shiba Inu Plunges: Will It Survive This Critical Test?
Shiba Inu Plunges: Will It Survive This Critical Test?
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin  Deskk

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

© Coindeskk News Network. All Rights Reserved.