4h ago
MEV Bot "Yoink" Front-Runs Ethereum rsETH Attack Attempt, Captures $7.8M
CoinMarketCap reported that an attempted large-scale exploit targeting rsETH on Ethereum was disrupted before it could be completed after an MEV bot stepped in. On-chain records show a bot dubbed "Yoink" executed a transaction ahead of the attacker in the same block, securing 2,900 rsETH worth about $7.8 million.
Security firms PeckShield and BlockSec said the activity occurred in Ethereum block 25980525. Yoink's transaction was ordered first, while the attacker's transaction was processed afterward and ultimately reverted. Researchers believe the bot detected a profitable opportunity in the mempool or during block construction, submitted a competing transaction, and won priority by paying higher fees.
Fund flows indicate that after receiving 2,900 rsETH, Yoink sent 2,882.37 rsETH to another address. The remaining 17.63 rsETH was routed through Uniswap v4, after which 18.95 ETH returned to the Yoink contract. Of that amount, 18.93 ETH was then paid to the block builder, suggesting most of the ETH was used to secure transaction ordering rather than retained as yield.
BlockSec attributed the underlying risk to a Safe module executor. The firm said an executor contract tied to a Safe-enabled module contains a flaw in its authorization checks, allowing attacker-controlled calls to enter a wallet's trusted execution path and trigger actions that should not be externally callable. Safe is a widely used smart-contract wallet framework that supports multisignature setups and optional modules. Current assessments point to specific wallet configurations and related executor issues, with no signs that Safe's core contracts were compromised.
Blockaid added that the attacker leveraged a public keeper multicall to route a custom Uniswap v4 liquidity module into a hook pool under the attacker's control, then decomposed aEthrsETH into rsETH, creating the assets contested in the transaction.
The ultimate destination of the funds remains unconfirmed. As of the report, the owner of the address that received 2,882.37 rsETH had not been identified, and it was unclear whether the assets would be returned. The report also did not say whether recovery efforts, bounty discussions, or legal action had begun.
The episode underscores that MEV is not limited to arbitrage and liquidation strategies: it can also influence who captures assets in the middle of an exploit attempt, where block position and priority fees can determine the final outcome.
DeFi security losses remain elevated in 2026. Figures cited in the article put attack-related protocol losses at no less than $1.3 billion in the first eight months of the year. rsETH was also tied to another security incident in April, though researchers said the attack paths differ.
The article noted that the U.S. Department of Justice has previously pursued criminal cases involving certain MEV-related conduct, but no regulator or law enforcement body has announced action related to the Yoink transaction.