An Ethereum maximal extractable value bot identified as Yoink front-ran an attempted Safe wallet exploit involving 2,900 rsETH worth approximately $7.8 million. The bot paid nearly 19 ETH to secure the first position in Ethereum block 25980525, according to blockchain security researchers.
BlockSec traced the vulnerability to faulty authorization checks in an executor contract linked to an enabled Safe module. Blockaid added that the attacker accessed a public keeper multicall and routed funds through a malicious Uniswap v4 hook pool, where aEthrsETH was unpacked into rsETH. PeckShield first identified the incident as an approximately $7.81 million attack involving rsETH, the liquid restaking token associated with KelpDAO.
On-chain data show Yoink received 2,900 rsETH at the top of the block, while the original exploit transaction ran later and reverted. The bot transferred 2,882.37 rsETH to address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0 and moved 17.63 rsETH through Uniswap v4 Pool Manager, which sent 18.95 ETH to Yoink and then 18.93 ETH to the block builder. Researchers said no information identified the address owner or whether funds would be returned.
The incident adds to a difficult year for decentralized finance. A September report cited CertiK and Forbes estimates that protocols lost at least $1.3 billion to exploits in the first eight months of 2026. Security firms did not connect this event to an April 2026 attack in which 116,500 unbacked rsETH were minted after infrastructure tied to a LayerZero verifier was compromised.
The term front-running does not by itself settle legal status. In May 2024, the U.S. Department of Justice charged two brothers over an alleged Ethereum scheme that obtained about $25 million in cryptocurrency within roughly 12 seconds. No U.S. action involving Yoink has been announced.