Overview
- The attempted extraction occurred Tuesday and involved about 2,900 rsETH that an attacker tried to move from a Gnosis Safe wallet before an MEV bot called Yoink beat the attacker and took the tokens.
- Researchers say the root cause was a weak authorization check in an executor contract tied to an enabled Safe module, which allowed external calls to reach trusted execution paths.
- The attacker used a public keeper multicall to steer a custom Uniswap v4 module into a malicious hook pool that unpacked aEthrsETH into rsETH, and that call was the opportunity Yoink front‑ran.
- On‑chain records show Yoink paid nearly 19 ETH to a block builder to secure first placement in block 25980525, sent 2,882.37 rsETH to address 0xC70f..., and routed about 17.63 rsETH through Uniswap v4.
- KelpDAO paused the receiving address for 24 hours and says rsETH remains fully collateralised, while no operator, attacker, or legal action has been publicly identified and recovery options remain uncertain.