NewsCryptoMEV Bot Yoink Front-Runs Reported $7.8 Million rsETH Exploit on Ethereum

MEV Bot Yoink Front-Runs Reported $7.8 Million rsETH Exploit on Ethereum

Author: AI Crypto Core·

Key Takeaways

  • The MEV bot Yoink secured block position zero in Ethereum block 25980525, withdrawing 2,899.99 rsETH worth about $7.48 million from Aave ahead of the original attack transaction, which then reverted.
  • Yoink forwarded 2,882.37 rsETH valued at approximately $7.43 million to an external address whose ultimate controller has not been identified.
  • Blockaid's detection system flagged an exploit on an unnamed Safe wallet with around $7.73 million in confirmed rsETH losses, while claims that Kelp DAO owned the wallet and froze funds lack first-party verification.
  • Because the apparent victim was a multisig Safe wallet, the exploit likely involved a compromised signer key, a maliciously approved transaction, or a module vulnerability rather than a simple private key breach.
  • The episode highlights mempool execution risk for liquid restaking tokens used as lending collateral, and no announcement of the captured funds being returned has been made.
MEV Bot Yoink Front-Runs Reported $7.8 Million rsETH Exploit on Ethereum

An MEV bot known as Yoink front-ran a reported rsETH exploit on Ethereum on September 15, 2026, withdrawing nearly 2,900 rsETH valued at approximately $7.8 million before the original attack transaction could execute, according to on-chain data and security researchers.

Key Points

  • MEV bot Yoink front-ran a reported rsETH exploit, landing at position zero in Ethereum block 25980525 on September 15, 2026.
  • Etherscan records the bot withdrawing 2,899.99 rsETH ($7,476,833.83) from Aave, then forwarding 2,882.37 rsETH ($7,431,373.16) to an external address.
  • The identity of the Safe wallet owner and the ultimate controller of the receiving address remain unconfirmed by any first-party statement.

rsETH is a liquid restaking token issued on Ethereum, representing staked ETH positions that accrue additional yield through restaking protocols. MEV, short for maximal extractable value, refers to profit captured by reordering, inserting, or censoring transactions within a block. Its deep integration with lending markets such as Aave means large positions can be withdrawn or liquidated through smart-contract calls, creating a target surface that MEV bots actively monitor in the public mempool.

First Public Attribution

Security firm PeckShield was among the first to characterize the event publicly, describing it as a front-run of a roughly $7.81 million rsETH exploit on Ethereum.

#PeckShieldAlert MEV bot yoink front-runs a ~$7.81M $rsETH exploit on Ethereum pic.twitter.com/vAJwsCOfsQ

— PeckShieldAlert (@PeckShieldAlert) September 15, 2026

Source: @PeckShieldAlert on X

The Transaction Sequence

According to Etherscan records for block 25980525, Yoink's transaction executed at 04:38:47 AM UTC on September 15, 2026. The bot withdrew 2,899.999999999997756819 rsETH, valued at $7,476,833.83 at execution, from Aave.

Yoink then forwarded 2,88237 rsETH, valued at $7,431,373.16, to the address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. The identity and ultimate controller of that receiving address have not been established by the available evidence.

The Defiant reported that Yoink and the original attack transaction landed in the same Ethereum block, with Yoink occupying position zero and the original attacker's transaction reverting. Achieving block position zero requires submitting a transaction with a higher priority fee or using a private relay, a technique common among professional MEV operators.

What Remains Unconfirmed

Security firm Blockaid said its exploit-detection system flagged an exploit on an unidentified user's Safe wallet on Ethereum, reporting approximately $7.73 million in confirmed rsETH loss. Blockaid did not publicly name the Safe owner.

Multiple secondary reports attributed the affected Safe to Kelp DAO and claimed the protocol froze related funds. No first-party statement from Kelp DAO, Safe, Aave, or the wallet owner was verified in the available evidence. Those claims should be treated as unconfirmed.

What the rsETH Exploit Means for DeFi Users and Protocols

Execution Risk in Public Mempools

The incident illustrates a structural tension in Ethereum's public mempool: any transaction broadcast without private relay infrastructure is visible to MEV bots before inclusion. In DeFi security incidents, this cuts both ways. A bot front-running an exploit may prevent a designated attacker from capturing funds, but the bot itself retains the proceeds rather than returning them to the affected party. Precedent is mixed: in earlier DeFi exploits, MEV bots that front-ran attackers have in some cases returned the captured funds afterward, and no such step has been announced in this case.

The outcome here, where roughly $7.4 million moved to an address of unknown ownership, mirrors patterns seen in earlier DeFi incidents. A prior DeFi bridge exploit involving fabricated BTC tokens similarly demonstrated how unauthorized token flows can cascade through interconnected protocol layers before any human response is possible.

Protocol Security Lessons

The use of a Safe multisig wallet as the apparent victim is notable. Safe is widely deployed by DAOs and institutional DeFi participants specifically because it requires multiple signers. An exploit targeting a Safe suggests either a compromised signer key, a malicious transaction approved by quorum, or a module vulnerability rather than a simple private key breach.

Aave's role as the liquidity layer from which the rsETH was withdrawn points to the compounding risk of using liquid restaking tokens as collateral in lending markets. Position sizes large enough to produce $7.4 million in a single withdrawal are inherently attractive MEV targets, regardless of whether the triggering transaction is an exploit or a routine liquidation. Protocol teams assessing similar collateral risks across other chains face comparable mempool exposure.

Limits of On-Chain Attribution

At the time of publication, Ethereum was trading at $2,412.37, up 0.14% over 24 hours, with the broader crypto market sentiment index registering 51 (Neutral). The macro backdrop did not amplify the incident's immediate price impact on rsETH or ETH.

On-chain data can confirm what moved, when, and to which addresses, but it cannot confirm intent, protocol attribution, or fund recovery without off-chain disclosure. Any further movement of the forwarded rsETH would be visible on public block explorers, yet attaching names or responsibility to those transfers would still require a first-party statement. Until the Safe owner, Kelp DAO if involved, or the controller of the receiving address issues a statement, the final disposition of the approximately $7.4 million in rsETH remains an open question for the Ethereum DeFi ecosystem.


Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Source: AI Crypto Core