BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

MEV Bot Yoink Stops $7.8M Ethereum rsETH Exploit in Its Tracks

Key Highlights A hacker attempted to drain $7.8 million worth of rsETH from an Ethereum Safe wallet through a vulnerability in a custom Uniswap v4 module An MEV bot named “Yoink” successfully

AnonymousCryptoCompass newsroom
September 16, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

Key Highlights

  • A hacker attempted to drain $7.8 million worth of rsETH from an Ethereum Safe wallet through a vulnerability in a custom Uniswap v4 module
  • An MEV bot named “Yoink” successfully front-ran the malicious transaction, securing the funds ahead of the would-be exploiter
  • The bot paid approximately 19 ETH to a block builder to guarantee first position in the transaction block
  • KelpDAO, rsETH’s issuing protocol, imposed a 24-hour freeze on the destination address as a security measure
  • Security firm BlockSec identified the issue as insufficient authorization verification in an executor contract associated with a Safe module

A sophisticated MEV bot operating under the name Yoink successfully thwarted a $7.8 million attempted heist of rsETH tokens on the Ethereum network, securing the digital assets before the malicious actor could complete the theft.

The attempted exploit occurred on September 15, 2026, within Ethereum block number 25980525. An unidentified threat actor sought to leverage a vulnerability in a customized module integrated with a Safe smart contract wallet.

Blockchain security company Blockaid reported that the hacker utilized a publicly accessible keeper multicall function to redirect assets through a compromised Uniswap v4 hook pool. The strategy involved converting aEthrsETH tokens into rsETH, KelpDAO’s liquid restaking token.

However, the attacker’s plan failed completely. Yoink, an automated program designed to identify and capitalize on profitable blockchain transaction opportunities, spotted the exploitation attempt and executed a front-running transaction.

The Mechanics Behind Yoink’s Successful Intervention

The Yoink bot secured 2,900 rsETH tokens at the beginning of the block. It subsequently transferred 2,882.37 rsETH to a different wallet address while directing the remaining 17.63 rsETH through the Uniswap v4 protocol.

The Pool Manager contract then returned approximately 18.95 ETH to Yoink’s contract address. The bot immediately forwarded 18.93 ETH to a block builder—this substantial payment functioned as Yoink’s competitive bid to secure priority transaction ordering within the block.

The hacker’s original exploitation attempt executed later in the identical block but failed and reverted. Cybersecurity analysts indicate that the transaction sequence demonstrates Yoink identified the attack vector and executed its countermeasure first.

BlockSec’s investigation revealed that inadequate authorization verification in an executor contract connected to the Safe wallet module was the underlying vulnerability. This security gap permitted external calls to pass through a pathway the wallet incorrectly treated as trustworthy.

Importantly, this vulnerability did not exist in Safe’s core smart contracts or Ethereum’s base protocol. The weakness was isolated to the specific executor contract deployed with that particular wallet configuration.

KelpDAO Implements Emergency Freezing Protocol

Following the incident, Kelp, the protocol responsible for rsETH, implemented a 24-hour pause on the address containing the recovered funds. This temporary restriction prevented any token transfers originating from that specific address.

Kelp emphasized that the freeze applied exclusively at the wallet level and that its core protocol contracts remained completely secure. Token minting operations, withdrawal processes, and third-party integrations continued functioning normally throughout the investigation period.

The protocol team verified that rsETH maintains full collateral backing and announced ongoing collaboration with cybersecurity specialists regarding the case.

This represents the second security event involving rsETH in 2026. Previously in April, a different attacker generated 116,500 unbacked rsETH tokens after breaching LayerZero verifier infrastructure, subsequently using those tokens as loan collateral on the Aave platform.

Security analysts have found no connection between these two separate incidents. Each exploitation attempt targeted distinct vulnerabilities and utilized different attack vectors.

The decentralized finance sector has experienced substantial losses throughout the year. According to CertiK and Forbes data referenced in a September analysis, DeFi protocols suffered over $1.3 billion in losses from security breaches during the first eight months of 2026.

As of this writing, no law enforcement agencies have announced investigations related to either the Yoink bot or the attempted rsETH exploitation. The identities of the attacker, Yoink’s operator, and the participating block builder remain undisclosed.

The post MEV Bot Yoink Stops $7.8M Ethereum rsETH Exploit in Its Tracks appeared first on Blockonomi.