🚨 MEV bot "yoink" front-runs a ~$7.81M rsETH exploit on Ethereum
An attacker deployed "Permissionless Attacker Token" and launched the exploit straight into the mempool where it was front-run by yoink capturing the entire ~$7.8M for itself.
Root cause: whale 0x40E9's leveraged rsETH funds sat in a Gnosis Safe whose strategy executor was a whitelisted Safe module. That module exposed a recipe entrypoint that forwarded fully caller-supplied calldata into the Safe's execTransactionFromModuleReturnData with operation=1 (DELEGATECALL) and no gating on the external caller. Because the module is already an authorized Safe module, anyone who could reach the entrypoint could execute arbitrary code in the Safe's own context - full control over its assets.
TX: https://etherscan.io/tx/0x0e7680b06cb8a6f86c149d9ba90d98e3d334e7b072dde03909d43fcfd98a8705
Victim (whale 0x40E9): https://etherscan.io/address/0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
Original exploiter: https://etherscan.io/address/0x0dC2c5D6b05A317076CF501f7E7be36a5dfe9b66
Frontrunner (yoink MEV bot): https://etherscan.io/address/0xfde0d1575ed8e06fbf36256bcdfa1f359281455a
⏱️ Real-time alerts: @defimon_subscription_bot
Post #3303
1.08K

- 🙉 6
- ❤ 2
- 🔥 1