A Bot Named Yoink Stole a Hacker's $7.8 Million rsETH Haul First

A hacker cracked open a $7.8 million Ethereum wallet on September 15, only to watch an automated bot called Yoink outrace him to the payout by about $47,000 in fees.

The victim was a Gnosis Safe wallet. It held a large position in aEthrsETH, the Aave-wrapped version of Kelp DAO's liquid restaking token rsETH. An attacker found a hole in a custom Safe module the wallet had authorized as a strategy executor, one built to automate a Uniswap v4 liquidity position. The module had a public DELEGATECALL entrypoint. Its permission check had a basic flaw: it approved any caller who simply named the module itself as the target.

The attacker used a public keeper multicall function to redirect the module toward a malicious Hook pool. From there he unpacked the wallet's aEthrsETH into roughly 2,900 raw rsETH, worth about $7.8 million, and sent the exploit transaction into Ethereum's public mempool.

That's where it went wrong for him.

A bot was already watching

An MEV bot named Yoink was watching the same mempool. It copied the attacker's own transaction, then paid around $47,000 in priority fees to jump the queue and get its version processed first. According to reporting from crypto.news, both transactions landed in the same Ethereum block, number 25980525, with Yoink's copy executing first and the original attacker's transaction reverting outright. The hacker had done the hard part: finding the bug, writing the exploit, timing the call. A bot took the money anyway.

Where the flaw actually sat

Multiple security firms picked the transaction apart within hours. Blockaid, BlockSec and SlowMist all reached the same conclusion: the flaw sat in a module the wallet owner had opted into, not in Safe's core smart contracts. Safe wallets let users bolt on custom modules for automation - in this case a router built to manage a Uniswap v4 liquidity position. The module's authorization check was supposed to confirm a call came from a trusted source. Instead, it accepted any caller that listed the module's own address as the target, a shortcut that let an outsider trigger a DELEGATECALL and run arbitrary logic inside the wallet's own context.

This isn't a new category of bug. DELEGATECALL misuse has drained Safe-style multisig wallets before, because it lets external code execute with the wallet's own permissions. What's unusual here is that the fix came from an opportunist, not a white hat.

What Kelp DAO did next

Kelp DAO moved fast once it saw the transfer. The protocol froze the destination address and paused rsETH transfers for 24 hours, a step it said was meant to preserve the funds for possible victim compensation rather than to protect its own contracts. The team also confirmed that Kelp's core rsETH contracts and the underlying collateral pool were never touched. The exploit lived entirely in a third-party module, not in the token itself.

Whether the original victim ever sees that $7.8 million again is an open question. Yoink is not a charity. MEV bots exist to extract value wherever they can find it, and this one found it sitting in a public mempool with no owner attached yet. Frankly, calling it vigilante justice gives the bot too much credit. It didn't catch a hacker. It beat one to the finish line, the same way it would beat any trader to an arbitrage opportunity.

What the episode shows, plainly, is how exposed a transaction becomes the moment it hits Ethereum's public mempool. If you're moving real money through a Safe wallet with third-party modules attached, this is your reminder that every permission you grant is a potential entry point. Anyone running a bot with enough gas and enough speed can watch, copy and outbid you, hacker or not. The rsETH heist just made that fact visible in a single, oddly satisfying block.

Also read: Forward Industries Raises SkyAI Bid to $2.13, Gets Rejected AgainCoinbase Shares Sink 10% After the Senate Rejects the CLARITY ActThe FCA Wants to Free Tokenized Gold From UK Fund Rules

This article is posted in Crypto News, check it out for more related stories.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论