Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Add preferred source
An MEV bot named Yoink intercepted roughly $7.7 million in rsETH before an attacker could complete an exploit targeting an Ethereum Safe wallet. The bot paid nearly 19 ETH to secure priority placement in block 25980525, capturing 2,900 rsETH before the original transaction reverted. BlockSec traced the vulnerability to faulty authorization checks in an executor contract linked to a Safe module, while Blockaid detailed how the attacker used a public keeper multicall to route a custom Uniswap v4 liquidity module into a malicious hook pool that unwrapped aEthrsETH into rsETH. Kelp, the protocol behind rsETH, placed the receiving address under a 24-hour transfer pause and stated its contracts remain secure and the token stays fully backed. The incident adds to a year of heavy DeFi losses exceeding $1.3 billion through August 2026.
Key Elements

An automated trading program beat a suspected attacker to the punch on Monday, intercepting roughly $7.7 million worth of rsETH before the original exploit transaction could complete. The episode, which unfolded in a single Ethereum block, has raised fresh questions about the security of modular wallet architectures and the role of MEV bots in mitigating—or profiting from—on-chain attacks.
Blockchain security firm PeckShield first flagged the incident as an approximately $7.81 million attack involving rsETH, the liquid restaking token issued by Kelp. The bot, known as Yoink, placed its transaction ahead of the suspected attacker in Ethereum block 25980525, capturing 2,900 rsETH before the original exploit attempt reverted later in the same block.
On-chain records show Yoink received the full 2,900 rsETH at the top of the block. From there, 2,882.37 rsETH was routed to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, where it remained at the time security researchers reviewed the transaction. The remaining 17.63 rsETH was sent through the Uniswap v4 Pool Manager, which then transferred 18.95 ETH back to the Yoink contract. Yoink forwarded 18.93 ETH—worth approximately $46,000 at the time—to the block builder.
That payment consumed nearly all of the ETH received from the Uniswap leg of the transaction, leaving little direct profit from that portion. Researchers interpreted the large builder payment as a bid for priority placement rather than a profit-taking move. A complete accounting of Yoink’s net position, including the retained rsETH and other costs, was not published in the initial reports.
How the Attack Was Constructed
BlockSec attributed the underlying vulnerability to faulty authorization checks in an executor contract linked to an enabled Safe module. Safe is a smart contract wallet system that allows multiple signers to approve transactions and supports add-on modules that can execute predefined actions without requiring manual signatures on every operation. When a module is enabled, it becomes part of the wallet’s security boundary.
According to BlockSec’s analysis, the affected executor failed to properly verify the authority behind incoming calls, letting an outside party reach functions through a route the wallet treated as trusted. The firm was careful to note that the flaw lay in the executor contract associated with the wallet configuration, not in Ethereum’s consensus system or the core Safe contracts themselves.
Blockaid provided a more granular account of the attack path. The security company said the attacker accessed a public keeper multicall and directed a custom Uniswap v4 liquidity module toward a hook pool under the attacker’s control. Uniswap v4 hooks are contracts that can execute custom logic at specific points in a pool’s operations. In this case, the malicious hook pool was used to unwrap aEthrsETH into rsETH, producing the tokens the attacker intended to extract.
“This is a precautionary, wallet-level measure only,” Kelp said in a statement posted on X. “Kelp contracts are safe, rsETH remains fully backed.”
The protocol confirmed that minting, withdrawals, and other integrations continued normally while security experts investigated. Kelp emphasized that only the custom module attached to the victim’s Safe was exploited, and that its own core contracts were unaffected.
The Bot’s Role and MEV Mechanics
The Yoink transaction and the original exploit attempt both landed in block 25980525. Yoink appeared at the top of the block, while the attacker’s transaction ran later and reverted. Security researchers viewed this ordering as evidence that the bot detected the attack in the mempool and moved first, submitting a competing transaction that captured the same output before the attacker could complete the withdrawal path.
This type of competition falls under maximal extractable value, or MEV, which arises from the ability to control transaction inclusion and ordering within blocks. Searchers scan pending transactions for profitable openings, assemble transaction bundles, and pay block builders to place them in advantageous positions. In this case, Yoink’s payment of nearly 19 ETH to the builder appears to have secured the top position in the block.
The incident does not mean the exploit attempt was prevented from being constructed. Rather, the MEV bot redirected the settlement outcome by capturing the assets before the attacker could complete the intended withdrawal.
A Year of Heavy DeFi Losses
The attempted extraction is part of a broader pattern of significant losses across decentralized finance in 2026. A September report on DeFi security losses cited estimates from CertiK and Forbes showing that protocols lost at least $1.3 billion to exploits during the first eight months of the year. The same report found that compromised credentials and privileged access had overtaken traditional smart contract flaws as the leading
rsETH has appeared in a separate major security event this year. In April, an attacker minted 116,500 unbacked rsETH after compromising infrastructure tied to a LayerZero verifier, then used the tokens as collateral on Aave to borrow other assets. Security researchers have not connected the April incident to the transaction in block 25980525, noting that the two events involved different reported weaknesses.
Legal Context and Unanswered Questions
For U.S. observers, the Yoink transaction illustrates why the term “front-running” does not by itself settle the legal status of an on-chain trade. Federal authorities have pursued certain MEV operations when prosecutors alleged that operators used deception or tampered with systems to obtain funds. In May 2024, the U.S. Department of Justice charged two brothers over an alleged Ethereum scheme that obtained about $25 million in cryptocurrency within roughly 12 seconds. Prosecutors alleged that Anton and James Peraire-Bueno manipulated the process Ethereum traders used to order transactions and fraudulently gained access to pending private transactions.
The Justice Department’s charges concerned the methods allegedly used to obtain trading information and manipulate the process, rather than treating every transaction-ordering strategy as automatically criminal. No U.S. regulator or law-enforcement agency has announced an action involving Yoink or the attempted rsETH exploit.
Several key questions remain unresolved. The reports cited by security researchers did not identify the suspected attacker, the Yoink operator, or the block builder. It was also unclear whether a recovery agreement, bounty negotiation, or legal process had begun. With Kelp’s 24-hour pause window as the immediate focal point, the next developments to watch include whether the paused address can be safely recovered, whether further addresses are linked to the same exploit chain, and whether similar module-based patterns emerge elsewhere.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
Source: finance.biggo.com

1 Comment
Pingback: Bitcoin Hits Three-Week Low as U.S. Senate Rejects Motion to Proceed on Crypto Regulation Bill – xpertsstudio