An MEV Bot Paid $47,000 to Front-Run a $7.73M Hack

A hacker drained $7.73M in rsETH from an Ethereum wallet. An MEV bot paid $47,000 in gas to front-run the transaction and took 99% of the funds.

Jan Whitfield News

The Exploit Worked. Then a Bot Took the Money.

A hacker drained 2,900 rsETH worth $7.73 million from an Ethereum Safe wallet on September 15 at 04:38 UTC. In the same block, an MEV bot named Yoink front-ran the transaction and walked away with 2,882 rsETH. The attacker got 18 tokens.

The exploit targeted wallet address 0x40E93a52F6Af9fCD3b476aeDADD7FeABD9f7AbA8 through a flaw in a custom Uniswap v4 module. A public keeper multicall routed an authorized Safe module into an attacker-created hooked pool. The hook converted aEthrsETH into transferable rsETH, bypassing the wallet's security layer.

According to the incident report, the vulnerability was not in Safe's core protocol. The wallet owner had granted unsafe permissions to a delegated module. That module became the attack surface. The exploit itself was sophisticated, but the real surprise came in the same block.

Yoink Paid $47,000 to Be First

MEV bots monitor the mempool for profitable transactions. When Yoink detected the rsETH extraction, it paid approximately $47,000 in gas fees to process its own transaction ahead of the attacker's. The bot captured 2,882 of the 2,900 stolen tokens and sent them to address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0.

The hacker's plan depended on dumping the rsETH into a liquidity pool built around a worthless token called "Permissionless Attacker Token." Yoink front-ran that dump, extracted the rsETH before the attacker could complete the swap, and routed the funds to a separate address. KelpDAO later placed that address under a temporary 24-hour pause.

The incident follows a string of cross-chain exploits this year. One hacking unit stole $578 million from DeFi protocols in an 18-day run earlier this spring. North Korean operatives have been tied to several wallet compromises. A separate bridge exploit in April minted $1 billion in fake tokens but netted only $237,000 in actual proceeds.

Custom Modules, Custom Risks

Safe wallets are widely used for their multisignature security model. The September 15 breach did not compromise that model. The flaw was in a third-party module the owner authorized. When that module routed a transaction to a malicious hook, the wallet executed the instruction without additional verification.

The attacker is still unidentified. Yoink's operator is also unknown. The 2,882 rsETH remains under KelpDAO's pause, but whether it will be returned to the original wallet owner or retained by Yoink is unclear.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.