NewsLayer.com
NewsLayer PulseLIVEBTC$75,641-2.53%ETH$2,396-3.99%SOL$96.92-4.32%XRP$1.29-8.03%DOGE$0.08-3.93%ADA$0.1947-5.13%Total Cap$2.70T-2.48%Layer Index25 Fear

CryptoDeFi

breaking

MEV Bot Front-Runs $7.8 Million rsETH Exploit on Ethereum

An MEV bot known as Yoink front-ran an exploit targeting a Safe wallet on Ethereum on Tuesday. PeckShield described the incident as an approximately $7.81 million rsETH exploit.

The Defiant

Publisher

Sep 15, 2026 at 9:08 PM UTC · Updated a few seconds ago · 1 min read

MEV Bot Front-Runs $7.8 Million rsETH Exploit on Ethereum
Image via The Defiant

Entities

ethereum

Last Updated

a few seconds ago

An MEV bot known as Yoink front-ran an exploit targeting a Safe wallet on Ethereum on Tuesday. PeckShield described the incident as an approximately $7.81 million rsETH exploit.

Onchain records show the Yoink transaction received 2,900 rsETH and sent 2,882.37 rsETH to `0xC70f00CD7E461686b04B0E912E309becA8b80ea0`. When checked, Etherscan displayed a balance of exactly 2,882.36740883 rsETH at that address.

The same transaction sent 17.63 rsETH to Uniswap's v4 Pool Manager. The pool sent 18.95 ETH to the Yoink contract, which forwarded 18.93 ETH to the block builder.

Yoink's transaction and the original attack transaction landed in Ethereum block 25980525 at 12:38 a.m. ET. The Yoink transaction occupied position zero in the block, while the original transaction encountered an execution revert. That ordering is consistent with security researchers' finding that Yoink front-ran the attack.

A Flawed Module Check

BlockSec attributed the exploit to a flawed authorization check in an executor contract connected to an enabled Safe module. The firm said attacker-controlled calls could execute through the trusted executor.

Blockaid said the attacker used a public keeper multicall to steer a custom Uniswap v4 liquidity module into an attacker-created hooked pool. The hook then unwrapped aEthrsETH into rsETH.

BlockSec said the exploit moved about 2,900 aEthrsETH into a Uniswap v4 pool paired with a token called Permissionless Attacker Token, leaving the Safe with a liquidity-position NFT. The identified target was an unidentified user's Safe using a custom module, according to Blockaid.

The address that received 2,882.37 rsETH in the Yoink transaction displayed 2,882.36740883 rsETH when checked.

Follow the Story

  1. Sep 15MEV Bot Front-Runs $7.8 Million rsETH Exploit on Ethereum
  2. Sep 16Bitcoin, Ethereum, XRP, Dogecoin Sink Amid Crypto Bill Failure, Rate Hike Expectations: Analyst Says 'Don
  3. Sep 16Top 3 Price Prediction: Bitcoin, Ethereum, Ripple – BTC, ETH and XRP retreat as Fed rate decision looms
  4. Sep 16Cryptocurrencies Price Prediction: Bitcoin, Pi Network & Ethereum – Asian Wrap 16 September

Sourced by

Originally reported by The Defiant

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

0

Applause

Was this article helpful?

Market Context

Ethereum

ETH

$2,394

-4.08% (24H)

Market Cap

$293.2B

24H Volume

$14.8B

24H High

$2,500

View Ethereum Market Page

Article Intelligence

Key Entities

Topics

Related Coverage

View all related

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium

Keep Reading

More from Crypto