PANews
PANews|Sep 16, 2026 04:35
[MEV Bot Yoink Front-Runs Hacker, Seizes 2,882 rsETH] According to CoinDesk, an attacker exploited a permission verification flaw in the Multicall contract authorized by the Safe multisig wallet, attempting to transfer approximately 2,900 rsETH (around $7.8 million). However, the automated trading bot Yoink detected the transaction in the public trading pool, paid approximately $47,000 in gas fees to front-run the transaction, and seized 2,882 rsETH, transferring them to another address. BlockSec, Blockaid, SlowMist, and AstraSec have all confirmed that the vulnerability lies in components authorized by users themselves, rather than the core Safe contract. The rsETH issuer, Kelp DAO, has implemented a 24-hour pause on the receiving address.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads