Bot Steals $7.8 Million from Hacker Who Stole It First
A hacker attempted to steal approximately $7.8 million worth of rsETH from Safe, Ethereum's safe wallet. However, the hacker was caught by a bot that stole the entire amount just seconds earlier.
The hack occurred on September 15, 2026, at UTC time. The hacker exploited the authorization path of an auxiliary contract called 'multicall' to redirect their own Uni V4 LP Safe module to a hooked pool created by the attacker.
A security platform called Blockaid was the first to detect the hack. According to Blockaid, the hack was not due to a flaw in the Safe core or the owner's private key but rather an exploitation of the authorization path of the auxiliary contract.
The bot that caught the hacker is named Yoink, an MEV (Maximal Extractable Value) bot that automatically searches for opportunities to profit by exploiting the order of transactions. Yoink preempts the attacker's own transactions, paying the block creator approximately $46,000 to have the transactions processed preferentially.
Kelp DAO, the issuer of rsETH, froze the address within two hours. It is unclear whether Yoink will return the funds. In a similar case in January 2026, MEV builders received approximately 10% of the stolen digital assets as rewards and returned the rest to their original owners.