A major attack attempt on rsETH on Ethereum was intercepted by a MEV bot before it could be successfully completed. Blockchain records show that a bot named Yoink executed a transaction within the same block before the original attack, taking away 2,900 rsETH, which is valued at approximately 7.8 million US dollars according to the text.
Robots complete transactions ahead of others.
Security agencies PeckShield and BlockSec tracking data on the blockchain indicate that this transaction occurred in Ethereum block 25980525. The transaction from Yoink was at the top of the block, and the original attack transaction was subsequently executed but then rolled back.
Based on this, researchers conclude that after robots identify exploitable paths during the memory pool or packaging phase, they submit competitive transactions in advance and obtain priority sorting by offering higher bids.
From the perspective of fund flow, after Yoink received 2,900 rsETH, it transferred 2,882.37 of them to another address, with the remaining 17.63 being routed through Uniswap and v4. Subsequently, 18.95 ETH were returned to the Yoink contract via that route, and of these, 18.93 were then transferred back to the block builder.
This means that the robots almost entirely use this portion of ETH to compete for priority positions within the block, rather than directly locking in the revenue from ETH.
The issue is directed at the Safe module executor.
BlockSec indicates that the root cause lies in an executor contract connected to a module that Safe has enabled, which has a flaw in its authorization verification. Calls controlled by attackers can utilize this executor to enter the wallet's trust path, thereby triggering operations that should not be directly invoked from the outside.
Safe is a common smart contract wallet system that supports multi-signature authentication and also allows accounts to enable modules to perform specific actions. Current statements from security institutions point to issues with the configuration of certain wallets and related executors, and there is no indication that the Safe core contract itself has been compromised.
Blockaid further stated that the attackers utilized a publicly available keeper to direct a custom Uniswap liquidity module to a pool under their control, hook. They then disassembled aEthrsETH into rsETH, which became the asset in dispute in this transaction.
The whereabouts of the funds are still to be confirmed.
As of the information cited in this report, the identities of the owners of addresses holding 2,882.37 rsETH have not been made public, and there is no conclusion as to whether the funds will be returned. The relevant reports also do not indicate whether any recovery efforts, bounty negotiations, or legal proceedings have been initiated.
This incident once again demonstrates that MEV is not merely a tool for arbitrage; it also gets involved in the scramble for assets during attacks. Who can enter the blockchain first and who is willing to pay a higher sorting cost often directly determine the ultimate destination of the funds.
In 2026, DeFi, security losses remained high. Statistics cited in the article show that in the first eight months of this year, losses caused by attacks on the protocol have reached at least $1.3 billion. rsETH was also involved in another security incident in April of this year, but researchers stated that the vulnerabilities involved in the two incidents were not the same.
Additional information:It is also mentioned in the text that the US Department of Justice has previously filed criminal charges against some MEV operations, but so far, no regulatory agency or law enforcement department has announced any action regarding this Yoink transaction.











