The incident involved an attempted theft of approximately $7.8 million in rsETH, a liquid restaking token associated with KelpDAO. Security firm BlockSec identified the vulnerability in an executor contract linked to a Safe module, which lacked sufficient authorization checks. This flaw allowed unauthorized calls to pass through an executor the wallet system treated as trusted, eventually enabling the attacker to route funds through a malicious Uniswap v4 hook pool.
Yoink detected the pending exploit and prioritized its own transaction by paying nearly 19 ETH to the block builder. This aggressive bidding secured the bot the first position in the block, effectively nullifying the attacker’s effort, which subsequently reverted. Following the interception, Yoink transferred 2,882.37 rsETH to a private address and routed the remaining 17.63 rsETH through the Uniswap v4 Pool Manager.
While the maneuver highlights the competitive nature of MEV in decentralized finance, it also underscores persistent security risks within modular smart contract architectures. Blockaid researchers noted that the attacker attempted to leverage a public keeper multicall to manipulate custom liquidity hooks, though no entity has yet claimed ownership of the Yoink bot or identified the original attacker. The event arrives amid a volatile year for DeFi, with industry reports estimating over $1.3 billion in losses due to exploits during the first eight months of 2026.

Comments (0)
No comments yet. Be the first!