KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
DeFi
Neutral

MEV Bot 'yoink' Preempts $7.8M rsETH Theft Attempt

Published September 20, 2026 12:51 AM · 1 views $RSETH
MEV Bot 'yoink' Preempts $7.8M rsETH Theft Attempt

An attempted theft of approximately $7.8 million (about 106 billion won) worth of rsETH—around 2,900 tokens—was preempted by an MEV bot named 'yoink.' The bot moved 2,882 rsETH tokens to another address during the process. CoinDesk reported on May 15 that the attacker sought to transfer assets by exploiting a permission verification flaw in Safe's Multicall contract, which had been approved by a Safe multi-signature wallet.

'Yoink' discovered the transaction in the public mempool and paid approximately $47,000 (about 64 million won) in fees to execute it first. BlockSec, Blockaid, SlowMist, and AstraSec confirmed the vulnerability originated not in Safe's core contract but in the permission verification of auxiliary components that users had directly approved. Kelp DAO, the rsETH issuer, implemented a 24-hour halt on the receiving address.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 2882 rsETH 가로챈 MEV 봇…세이프 승인 보조 구성요소 권한 결함 악용