Yoink Bot Foils $7.8 Million Ethereum Exploit
A sophisticated MEV bot known as Yoink front-ran an exploit targeting a Safe wallet on Ethereum, potentially saving millions of dollars in losses.
The incident occurred on Tuesday when an attacker attempted to steal $7.81 million worth of rsETH from the wallet. However, before the attacker's transaction could be executed, Yoink intervened and sent 2,882.37 rsETH to a different address, effectively front-running the attack.
According to onchain records, the transaction received by Yoink contained 2,900 rsETH and sent it to `0xC70f00CD7E461686b04B0E912E309becA8b80ea0`, which had a balance of exactly 2,882.36740883 rsETH.
The exploit was attributed to a flawed authorization check in an executor contract connected to an enabled Safe module by CheckBlockSec. Blockaid also analyzed the incident and found that the attacker used a public keeper multicall to steer a custom Uniswap v4 liquidity module into an attacker-created hooked pool, which then unwrapped aEthrsETH into rsETH.