BTC $76,592.60 -3.30%
ETH $2,429.10 -4.33%
BNB $721.40 -0.78%
XRP $1.39 -4.07%
SOL $99.57 -3.60%
TRX $0.3325 -2.33%
DOGE $0.0816 -3.82%
ADA $0.2013 -5.80%
BCH $221.59 -2.58%
LINK $11.24 -3.42%
HYPE $77.19 -5.46%
AAVE $125.80 -1.92%
SUI $0.7033 -4.67%
XLM $0.1893 -2.46%
ZEC $1,127.23 -4.26%
AAPL $330.57 -1.16%
AMZN $248.69 -2.48%
GOOGL $344.14 -1.00%
MSFT $498.54 -1.75%
META $670.08 +0.39%
NVDA $212.21 -0.04%
TSLA $358.08 -0.85%
SNDK $1,518.31 -2.95%
INTC $97.24 -1.46%
SPCX $144.63 -4.38%
MU $923.99 -0.57%
AMD $504.66 +1.59%
BTC $76,592.60 -3.30%
ETH $2,429.10 -4.33%
BNB $721.40 -0.78%
XRP $1.39 -4.07%
SOL $99.57 -3.60%
TRX $0.3325 -2.33%
DOGE $0.0816 -3.82%
ADA $0.2013 -5.80%
BCH $221.59 -2.58%
LINK $11.24 -3.42%
HYPE $77.19 -5.46%
AAVE $125.80 -1.92%
SUI $0.7033 -4.67%
XLM $0.1893 -2.46%
ZEC $1,127.23 -4.26%
AAPL $330.57 -1.16%
AMZN $248.69 -2.48%
GOOGL $344.14 -1.00%
MSFT $498.54 -1.75%
META $670.08 +0.39%
NVDA $212.21 -0.04%
TSLA $358.08 -0.85%
SNDK $1,518.31 -2.95%
INTC $97.24 -1.46%
SPCX $144.63 -4.38%
MU $923.99 -0.57%
AMD $504.66 +1.59%
first_img

MEV robot front-running trade 7.8 million USD rsETH attack

2026-09-16 00:14:46

An MEV bot named Yoink on Ethereum front-ran an exploit attack targeting the Safe wallet, which PeckShield referred to as an approximately $7.81 million rsETH attack. On-chain records show that the Yoink transaction received 2,900 rsETH and sent 2,882.37 rsETH to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, which currently has a balance of 2,882.36740883 rsETH.

The same transaction also sent 17.63 rsETH to the Uniswap v4 Pool Manager, which sent 18.95 ETH to the Yoink contract, which then transferred 18.93 ETH to the block builder. The Yoink transaction and the original attack transaction both occurred in Ethereum block 25980525, with the Yoink transaction at the top of the block, and the original transaction executed a rollback, consistent with the front-running judgment of security researchers.

BlockSec attributed the vulnerability to a flaw in the authorization checks of the executor contract associated with the enabled Safe module, allowing calls controlled by the attacker to be executed through a trusted executor. Blockaid stated that the attacker exploited a public keeper multi-call to direct a custom Uniswap v4 liquidity module to a hook pool created by the attacker, which subsequently unpacked aEthrsETH into rsETH.

app_icon
ChainCatcher Building the Web3 world with innovations.