MEV bot \u0022Yoink\u0022 frontruns $7.81M rsETH exploit on Ethereum

AI Market Summary
An MEV bot (Yoink) frontran and effectively neutralized a ~$7.81m rsETH exploit tied to a Safe wallet module executor authorization-check flaw, causing the original attacker's transaction to revert. While losses appear contained in this instance, the incident highlights persistent smart-contract and wallet-module attack surfaces and MEV-driven execution risk on Ethereum, which can pressure near-term sentiment and elevate security scrutiny across DeFi integrations.
Impact level
● Medium
Affected assets
ETH/USDT-5.84%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainCatcher reported that an MEV bot dubbed \u0022Yoink\u0022 frontran an exploit attempt on Ethereum tied to a vulnerability affecting Safe wallets. PeckShield estimated the incident as a $7.81 million rsETH attack. On-chain data shows the Yoink transaction received 2,900 rsETH and sent 2,882.37 rsETH to 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, which currently holds 2,882.36740883 rsETH. The transaction also routed 17.63 rsETH to the Uniswap v4 Pool Manager, after which 18.95 ETH was sent to the Yoink contract. The contract then forwarded 18.93 ETH to the block builder. Both the Yoink transaction and the original attack transaction landed in Ethereum block 25980525. Yoink\u0027s transaction was ordered first, and the attacker\u0027s transaction reverted, aligning with security researchers\u0027 view that a frontrunning strategy was used. BlockSec said the issue stemmed from a flawed authorization check in an executor contract tied to an enabled Safe module, enabling malicious calls to run through a trusted executor. Blockaid added that the attacker leveraged publicly accessible keeper multicalls to steer a custom Uniswap v4 liquidity module into an attacker-created hook pool, which then unpacked aEthrsETH into rsETH.