MEV Bot Frontruns $7.8M rsETH Exploit on Ethereum
An automated trading bot known as Yoink intercepted a major exploit attempt on the Ethereum network, capturing approximately 2,900 rsETH tokens worth about $7.8 million before the attacker could secure them. The incident, which occurred on September 15, 2026, involved a flawed authorization check in an auxiliary contract linked to a user's Safe wallet, not a vulnerability in Safe's core contracts, according to security firms BlockSec, Blockaid, and SlowMist. The exploit targeted a custom module connected to an Ethereum Safe wallet belonging to an unidentified user. The attacker used a public keeper multicall to route funds through a malicious Uniswap v4 hook pool, designed to unwrap aEthrsETH into the liquid restaking token rsETH, issued by KelpDAO. However, the MEV bot Yoink detected the pending malicious transaction and frontran it, paying nearly 19 ETH to a block builder to secure priority placement in Ethereum block 25980525. Onchain data shows Yoink received the 2,900 rsETH before the original exploit transaction reverted. The bot then transferred 2,882.37 rsETH to a separate address, while routing the remainder through a Uniswap v4 pool.