MEV Bot Foils $7.8M rsETH Exploit Attempt on Ethereum
A recent exploit attempt involving $7.8 million in rsETH tokens was front-ran by an Ethereum MEV bot named Yoink, which secured the first position in a block and received nearly 19 ETH as payment.
According to BlockSec, the underlying weakness was attributed to faulty authorization checks in an executor contract linked to a Safe module. The affected executor failed to confirm the authority behind a call correctly, allowing an outside party to reach functions through a trusted route.
The attacker attempted to use a public keeper multicall and directed a custom Uniswap v4 liquidity module toward a hook pool under their control. However, Yoink's bot detected the opportunity and submitted a competing transaction that captured the same output, ultimately landing in block 25980525.