Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
MEV bot Yoink front-runs $7.8 million crypto heist on Ethereum
00

MEV bot Yoink front-runs $7.8 million crypto heist on Ethereum

Sep 15, 2026

On September 15, 2026, an attacker targeted an unidentified user's Gnosis Safe wallet on Ethereum, attempting to drain 2,900 rsETH ($7.8 million) via a flawed Multicall helper contract. However, an automated MEV bot named Yoink front-ran the transaction, paying $47,000 to secure position zero in block 25980525 and capturing the tokens. Security firms confirmed Safe's core contracts were secure. Kelp DAO temporarily paused the receiving address and assured users that rsETH remains fully collateralized.

Gnosis Safe wallet exploit

  • ▪An attacker targeted an unidentified user's Gnosis Safe wallet on Ethereum on September 15, 2026, attempting to drain approximately 2,900 rsETH worth about $7.8 million
  • ▪The attacker attempted to dump the 2,900 rsETH into a Uniswap v4 trading pool paired with a worthless token named 'Permissionless Attacker Token,' leaving the victim's wallet with a valueless liquidity-position NFT

Yoink MEV bot front-running

  • ▪The Yoink bot paid approximately $47,000 to jump the queue, landing its transaction at position zero in Ethereum block 25980525 while the original attack transaction reverted
  • ▪The Yoink bot sent 2,882.37 rsETH to the Ethereum address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0 and 17.63 rsETH to Uniswap's v4 Pool Manager
  • ▪An automated MEV trading bot named Yoink front-ran the attack transaction on September 15, 2026, extracting the 2,900 rsETH from the public queue

Flawed authorization check vulnerability

  • ▪Security firms BlockSec, Blockaid, SlowMist, AstraSec, and PeckShield analyzed the exploit, confirming the vulnerability was in a custom module rather than Safe's core contracts
  • ▪The Multicall contract's authorization check was flawed because it approved any caller that named the contract itself as its target, allowing unauthorized calls to execute

Security firm incident analysis

  • ▪Blockaid reported that the attacker used a public keeper multicall to steer a custom Uniswap v4 liquidity module into an attacker-created hooked pool to unwrap aEthrsETH
  • ▪Kelp DAO placed a temporary 24-hour pause on the Ethereum address that received the rsETH from the Yoink transaction to prevent funds from moving

KelpDAO temporary address pause

  • ▪Kelp DAO, the issuer of rsETH, stated that its contracts are secure and that rsETH remains fully collateralized
  • ▪Kelp DAO detected potential suspicious activity on the address receiving the rsETH a few hours after the September 15, 2026 exploit

2 sources

Coindesk
A $7.8 million crypto heist was just hijacked by a bot named Yoink
View source article
Thedefiant
MEV Bot Front-Runs $7.8 Million rsETH Exploit on Ethereum
View source article

Story comments

Loading comments…

Related Projects

Gnosis SafeEthereum

Topics

Ethereum MEV & block buildingEthereum securityDeFi