MEV Bot Front-Runs $7.8 Million rsETH Exploit on Ethereum
An MEV bot called Yoink front-ran an exploit aimed at a Safe wallet on Ethereum, intercepting roughly 2,900 rsETH as the attacker’s transaction reverted. Security firms PeckShield, BlockSec and Blockaid attributed the incident to a flawed authorization check in an executor contract tied to a custom Safe module and to manipulation of a Uniswap v4 liquidity module.

Why It Matters
The event shows how MEV bots can capture or redirect funds when malicious transactions and miner ordering interact, and it underscores risks from buggy module logic and composability in DeFi systems such as Safe modules and Uniswap v4 liquidity hooks.
Key Facts
- MEV bot: Yoink
- Targeted asset: rsETH / aEthrsETH
- Amount Yoink received: 2,900 rsETH
- Amount forwarded to address: 2,882.36740883 rsETH (displayed balance)
- Additional transfers: 17.63 rsETH to Uniswap v4 Pool Manager; pool sent 18.95 ETH to Yoink contract; Yoink forwarded 18.93 ETH to block builder
An MEV bot called Yoink preempted an exploit against a Safe wallet on Ethereum by placing its transaction ahead of the attacker’s in the same block, according to onchain records and security researchers. PeckShield characterized the incident as an approximately $7.81 million rsETH exploit. Both Yoink’s transaction and the attacker’s transaction were included in block 25980525 at 12:38 a.m. ET; Yoink’s entry occupied position zero while the original attack reverted during execution.
Onchain data show Yoink’s transaction received about 2,900 rsETH and forwarded 2,882.37 rsETH to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, which displayed a balance of 2,882.36740883 rsETH when checked. The same transaction moved 17.63 rsETH to Uniswap’s v4 Pool Manager. That pool then sent 18.95 ETH to the Yoink contract, which subsequently forwarded 18.93 ETH to the block builder.
Security firms investigating the incident traced the exploit to a flawed authorization check in an executor contract associated with an enabled Safe module. BlockSec said the executor’s authorization logic allowed attacker-controlled calls to execute through the trusted executor. Blockaid reported the attacker leveraged a public keeper multicall to direct a custom Uniswap v4 liquidity module into an attacker-created hooked pool, and the hook was used to unwrap aEthrsETH into rsETH.
According to BlockSec, the exploit routed roughly 2,900 aEthrsETH into a Uniswap v4 pool paired with a token labeled Permissionless Attacker Token, leaving the targeted Safe holding a liquidity-position NFT. Blockaid identified the target as an unnamed user’s Safe that used a custom module. The observed ordering in the block and the revert of the original attack transaction are consistent with Yoink having front-ran the exploit.
Keep Reading

Solana Treasury Firm DeFi Dev Corp Rolls Out $300M CHAD to Buy More SOL

Crypto's Long-Sought 'De Minimis' Tax Break Gets a House Markup This Week

US Seeks Forfeiture of $61 Million in Crypto Linked to Alleged Iranian Oil Scheme
