$7.7M rsETH Hijacked: Yoink Bot Beats Attacker to Punch
A significant on-chain incident occurred on Monday when an automated trading program, Yoink, intercepted approximately $7.7 million worth of rsETH before a suspected attacker could execute their exploit attempt.
The attack was aimed at extracting rsETH, the liquid restaking token issued by Kelp, through a vulnerable executor contract linked to an enabled Safe module.
Kelp's contracts are safe, and rsETH remains fully backed, according to the protocol. However, only the custom module attached to the victim's Safe was exploited, leaving the core contracts unaffected.