Key Takeaways
- A malicious actor attempted to drain $7.8 million worth of rsETH from an Ethereum Safe wallet by exploiting a custom Uniswap v4 module
- The MEV bot known as “Yoink” successfully front-ran the malicious transaction, securing the funds ahead of the would-be exploiter
- Yoink invested approximately 19 ETH in payments to a block builder to guarantee top position within the block
- KelpDAO, the organization managing rsETH, implemented a 24-hour freeze on the recipient address as a protective measure
- Security firm BlockSec identified the source of the vulnerability as insufficient authorization validation in an executor contract associated with a Safe module
A maximal extractable value (MEV) bot operating under the name Yoink successfully prevented a $7.8 million heist of rsETH tokens on the Ethereum blockchain by securing the assets before the initial attacker could complete their exploit.
The event unfolded on September 15, 2026, during the processing of Ethereum block 25980525. An unidentified threat actor attempted to leverage a specially crafted module connected to a Safe protocol smart contract wallet.
Blockchain security company Blockaid reported that the adversary utilized a publicly accessible keeper multicall function to redirect assets through a compromised Uniswap v4 hook pool. This technique enabled the conversion of aEthrsETH tokens into rsETH, the liquid restaking asset associated with the KelpDAO ecosystem.
However, the malicious actor failed to obtain the targeted funds. Yoink, an automated transaction monitoring bot designed to identify and capitalize on profitable blockchain opportunities, identified the exploitation attempt and executed a faster competing transaction.
The MEV Bot’s Winning Strategy
Yoink successfully claimed 2,900 rsETH at the beginning of the block sequence. The bot then transferred 2,882.37 rsETH to a different wallet address while channeling the remaining 17.63 rsETH through the Uniswap v4 protocol.
Subsequently, the Pool Manager returned approximately 18.95 ETH to the Yoink contract address. From this amount, Yoink transmitted 18.93 ETH to a block builder. This substantial payment represented the bot’s competitive bid to secure preferential transaction ordering within the block.
The initial exploitation transaction executed later within the identical block but failed to complete successfully. Security analysts indicate that this transaction sequence demonstrates Yoink’s ability to identify and preempt the attack.
BlockSec’s investigation revealed that inadequate authorization verification within an executor contract connected to the Safe wallet module created the vulnerability. This design flaw permitted external function calls to traverse a pathway that the wallet system considered secure and authorized.
Importantly, this vulnerability did not stem from issues within Safe’s core smart contracts or the Ethereum protocol itself. The security weakness existed exclusively within the executor contract associated with this specific wallet configuration.
KelpDAO Takes Emergency Action
KelpDAO, the protocol responsible for managing rsETH, quickly imposed a 24-hour restriction on the address containing the recovered funds immediately following the incident. This emergency pause prevented any token movements from the affected address.
KelpDAO clarified that this protective action applied only to the specific wallet address and that the protocol’s core smart contracts maintained their security integrity. Token minting operations, withdrawal functions, and protocol integrations continued operating without disruption throughout the investigation period.
The protocol team verified that rsETH maintains complete collateralization and announced their collaboration with cybersecurity specialists to investigate the matter thoroughly.
This incident marks the second security challenge for rsETH in 2026. Previously in April, a different attacker successfully minted 116,500 unbacked rsETH tokens following a compromise of LayerZero verifier infrastructure and subsequently deployed those tokens as collateral on the Aave lending platform.
Cybersecurity analysts have found no connection between these two separate incidents. Each exploitation utilized distinct vulnerabilities and followed different attack vectors.
The decentralized finance sector has experienced substantial financial losses throughout 2026. Data from CertiK and Forbes referenced in a September analysis indicates that DeFi protocols suffered over $1.3 billion in losses from security exploits during the first eight months of the year.
As of this writing, no law enforcement agencies have publicly announced investigations related to the Yoink bot or the attempted rsETH exploitation. The identities of the attacking party, the Yoink bot operator, and the block builder involved remain undisclosed.


