Security· ★★★· neutral·

MEV bot Yoink intercepts 2,882 rsETH from hacker who attacked Safe wallet

  • The attack exploited a permission-check vulnerability in a Multicall contract, not in Safe's core
  • The yoink bot paid ~$47,000 in fees and seized 2,882 rsETH
  • Damage was estimated at ~$7.8 million (about 2,900 rsETH)
  • Kelp DAO imposed a 24-hour pause on the recipient address
Why it matters: The incident shows that MEV bots can outpace hackers and recover assets, but vulnerabilities in user permissions remain a risk for DeFi.
Source: PANews