Yoink Captures $7.8 Million rsETH Exploit Before Original Attacker
An Ethereum MEV bot called Yoink front-ran an attempted Safe wallet exploit involving about 2,900 rsETH worth $7.8 million on Tuesday. Yoink secured the first transaction position in the block and captured the tokens before the original attacker could complete the theft.
Security firms traced the exploit to a flawed authorization check in an auxiliary executor contract connected to the victim’s Safe module. The weakness allowed an attacker to route the wallet’s trading module into a malicious Uniswap v4 pool. That pool then converted the wallet’s Aave-wrapped rsETH position into transferable rsETH. The exploit targeted a user-configured component rather than Safe’s core contracts.
Yoink paid roughly 19 ETH, or about $47,000, to jump ahead in the transaction queue. The bot moved 2,882 rsETH to a separate address and routed the remaining amount through Uniswap. Kelp DAO later placed a temporary 24-hour pause on the receiving address while investigating. The protocol said its core contracts and rsETH backing remained unaffected.
Why it matters
The incident highlights how public mempools can expose profitable exploits to competing MEV searchers. It also shows that wallet security can depend heavily on third-party modules and authorization logic.


