Ethereum: Ethereum MEV Bot Launches a $7.8 Million rsETH Attack
Cryptonews
19h ago
Ai Focus
An attack attempt on Ethereum worth approximately $7.8 million rsETH was preempted by a MEV bot, exposing authorization verification issues with the executor related to the Safe module.
Helpful
No.Help

A major attack attempt on rsETH on Ethereum was intercepted by a MEV bot before it could be successfully completed. Blockchain records show that a bot named Yoink executed a transaction within the same block before the original attack, taking away 2,900 rsETH, which is valued at approximately 7.8 million US dollars according to the text.

Robots complete transactions ahead of others.

Security agencies PeckShield and BlockSec tracking data on the blockchain indicate that this transaction occurred in Ethereum block 25980525. The transaction from Yoink was at the top of the block, and the original attack transaction was subsequently executed but then rolled back.

Based on this, researchers conclude that after robots identify exploitable paths during the memory pool or packaging phase, they submit competitive transactions in advance and obtain priority sorting by offering higher bids.

From the perspective of fund flow, after Yoink received 2,900 rsETH, it transferred 2,882.37 of them to another address, with the remaining 17.63 being routed through Uniswap and v4. Subsequently, 18.95 ETH were returned to the Yoink contract via that route, and of these, 18.93 were then transferred back to the block builder.

This means that the robots almost entirely use this portion of ETH to compete for priority positions within the block, rather than directly locking in the revenue from ETH.

The issue is directed at the Safe module executor.

BlockSec indicates that the root cause lies in an executor contract connected to a module that Safe has enabled, which has a flaw in its authorization verification. Calls controlled by attackers can utilize this executor to enter the wallet's trust path, thereby triggering operations that should not be directly invoked from the outside.

Safe is a common smart contract wallet system that supports multi-signature authentication and also allows accounts to enable modules to perform specific actions. Current statements from security institutions point to issues with the configuration of certain wallets and related executors, and there is no indication that the Safe core contract itself has been compromised.

Blockaid further stated that the attackers utilized a publicly available keeper to direct a custom Uniswap liquidity module to a pool under their control, hook. They then disassembled aEthrsETH into rsETH, which became the asset in dispute in this transaction.

The whereabouts of the funds are still to be confirmed.

As of the information cited in this report, the identities of the owners of addresses holding 2,882.37 rsETH have not been made public, and there is no conclusion as to whether the funds will be returned. The relevant reports also do not indicate whether any recovery efforts, bounty negotiations, or legal proceedings have been initiated.

This incident once again demonstrates that MEV is not merely a tool for arbitrage; it also gets involved in the scramble for assets during attacks. Who can enter the blockchain first and who is willing to pay a higher sorting cost often directly determine the ultimate destination of the funds.

In 2026, DeFi, security losses remained high. Statistics cited in the article show that in the first eight months of this year, losses caused by attacks on the protocol have reached at least $1.3 billion. rsETH was also involved in another security incident in April of this year, but researchers stated that the vulnerabilities involved in the two incidents were not the same.

Additional information:It is also mentioned in the text that the US Department of Justice has previously filed criminal charges against some MEV operations, but so far, no regulatory agency or law enforcement department has announced any action regarding this Yoink transaction.

Tip
$0
Like
0
Save
0
Views 65
HKWDB reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Solana Mainnet enables 4096-byte transactions: More space, but also brings upgrade pressure on indexers
Solana will enable v1 transaction-related functions on the mainnet Epoch on September 15th at 01:20 UTC. The maximum size of a single transaction will be increased from 1232 bytes to 4096 bytes, which is approximately 3.3 times the original size. The official upgrade page indicates that the activation is expected to occur at this time, and the mainnet status will be marked as activated. The new format provides more space for zero-knowledge proofs, large multi-signatures, batch processing, and some on-chain signature schemes, reducing the need for developers to split a single operation into multiple transactions. The existing legacy and v0 transactions will continue to function, so this is not a hard fork that requires all wallets and applications to switch immediately.
币界网
·2026-09-16 10:17:03
203
Final Launches Shannon Development Network: An "Adaptive Blockchain" Begins with Restricted Testing
The new public chain Final announced on September 15th that its first major version, Shannon, is already running on the development network. The project positions itself as an “adaptive blockchain network” and showcases a structure composed of a main chain and a transaction chain, with plans to provide core facilities such as derivatives, spot trading, and stablecoins at the protocol layer. What needs to be clarified at this point is that what has been launched is Devnet, not the mature mainnet intended for everyone. The official website states that Shannon will be open to the public “in the near future,” and the current page still provides an application access link; functions such as wallets, bridges, and documentation are also marked as upcoming.
币界网
·2026-09-16 10:15:56
182
Canadian wholesale sales rose slightly by 0.3% in July: Building materials saw strength, but actual sales decreased by 0.6%
On September 15, Statistics Canada announced that in July 2026, wholesale sales increased by 0.3% month-on-month at current prices, reaching C$91.4 billion. This figure does not include oil, petroleum products, and other hydrocarbons, nor does it include oilseeds and grains. On the surface, there was little change in sales amounts, with growth even observed in the building materials and food sectors; however, when calculated at constant prices, total sales volume decreased by 0.6%. The increase in nominal amounts while the actual quantity decreased indicates that price factors supported the data for that month, and it also serves as a reminder to the market that one positive growth figure alone should not be used to conclude that demand has strengthened.
币百科
·2026-09-16 10:14:46
45
UK job vacancies drop to 702,000: Employment hasn't stopped abruptly, but corporate recruitment has returned to levels seen a decade ago
The Office for National Statistics in the UK released the latest labor market data on September 15. From June to August 2026, there were an estimated 702,000 job vacancies, which is a decrease of 8,000 from March to May, representing a 1.1% decline. Excluding the pandemic period, the last time there were 702,000 or fewer job vacancies was from August to October 2014, when there were 701,000 vacancies. Meanwhile, the unemployment rate from May to July was estimated at 4.9%, and the employment rate was 75.1%; average regular wages increased by 3.5% year-on-year, while total wages including bonuses grew by 3.9%. These figures indicate a market where recruitment demand remains low and wage growth is slowing down.
币百科
·2026-09-16 10:13:39
47
Google Launches Engineering Center in Singapore: The Next Step for AI Competition is to Turn Research into a Deployable System
Google Cloud launched on September 15th in Singapore as Singapore Engineering Center. This is not a traditional regional sales or after-sales office. According to the company's positioning, the center will bring together professionals in AI, machine learning, data, computing, core networking, storage, and frontline support, working together with enterprises to transform basic research into deployable cloud and AI systems. It is located at the same site as Google DeepMind's first research laboratory in Southeast Asia, aiming to bring research, product engineering, and customer implementation closer together on a shorter chain of operations. Google also mentioned that the center had already been publicly announced in February of this year.
CoinMeta
·2026-09-16 10:12:25
52
View More