MEV bot \u0022Yoink\u0022 frontruns $7.81M rsETH exploit on Ethereum

AI مارکیٹ کا خلاصہ
An MEV bot (Yoink) frontran and effectively neutralized a ~$7.81m rsETH exploit tied to a Safe wallet module executor authorization-check flaw, causing the original attacker's transaction to revert. While losses appear contained in this instance, the incident highlights persistent smart-contract and wallet-module attack surfaces and MEV-driven execution risk on Ethereum, which can pressure near-term sentiment and elevate security scrutiny across DeFi integrations.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT-5.32%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
ChainCatcher reported that an MEV bot dubbed \u0022Yoink\u0022 frontran an exploit attempt on Ethereum tied to a vulnerability affecting Safe wallets. PeckShield estimated the incident as a $7.81 million rsETH attack. On-chain data shows the Yoink transaction received 2,900 rsETH and sent 2,882.37 rsETH to 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, which currently holds 2,882.36740883 rsETH. The transaction also routed 17.63 rsETH to the Uniswap v4 Pool Manager, after which 18.95 ETH was sent to the Yoink contract. The contract then forwarded 18.93 ETH to the block builder. Both the Yoink transaction and the original attack transaction landed in Ethereum block 25980525. Yoink\u0027s transaction was ordered first, and the attacker\u0027s transaction reverted, aligning with security researchers\u0027 view that a frontrunning strategy was used. BlockSec said the issue stemmed from a flawed authorization check in an executor contract tied to an enabled Safe module, enabling malicious calls to run through a trusted executor. Blockaid added that the attacker leveraged publicly accessible keeper multicalls to steer a custom Uniswap v4 liquidity module into an attacker-created hook pool, which then unpacked aEthrsETH into rsETH.