0x178cbef2178c…178cbef5
Yoink Bot Front-Runs Hacker to Capture $7.8M rsETH on Ethereum
On September 15, 2026, an MEV bot called Yoink paid ~$46K to a block builder and outbid a hacker to capture $7.8M in rsETH from a misconfigured Safe wallet, leaving Kelp DAO's recovery path unresolved.
![MEV Bot Yoink Front-Runs $7.8M Ethereum Hack [2026] - shattered.io](/media/2026/10/b6f796123acfea8e.png)
Outputs
On September 15, 2026, MEV bot Yoink captured ~$7.8M in rsETH by outbidding an attacker's transaction with an ~18.93 ETH (~$46,000) builder payment.
The targeted Safe 1.3.0 multisig held close to 2,900 rsETH and was drained via a configuration flaw, not a core Safe contract bug.
Relay-monitoring data for Aug 29, 2026 showed Ultra Sound (35.1%) and bloXroute (23.8%) built the bulk of 11,656 MEV-Boost blocks tracked in 24 hours.
MEV-Boost adoption sits at ~92% of staked Ethereum validators, and 2026 industry estimates peg annual Ethereum MEV at ~$2.5 billion.
Kelp DAO earlier in 2026 sued LayerZero Labs over a separate $292 million rsETH exploit still in legal proceedings.
An automated trading program known on-chain as Yoink intercepted roughly $7.8 million in rsETH on September 15, 2026, paying about 18.93 ETH (close to $46,000) to an Ethereum block builder to win the race against a hacker draining a misconfigured Safe wallet. The original attacker walked away with nothing. Whether Kelp DAO or its token holders will recover the funds remains an open question.
What actually happened to the Safe wallet?
The target was a Safe multisig built on the Safe 1.3.0 contract standard, holding close to 2,900 rsETH, Kelp DAO's liquid restaking token. An attacker found a configuration flaw in the wallet's signing setup and crafted a drain transaction. Yoink spotted the exploit sitting in Ethereum's public mempool, copied its logic, and submitted a competing bundle with a higher builder payment.
Block builders pack the highest-paying valid bundle, not the first one submitted. That auction rule is what let Yoink win. Once the bot's transaction landed, the vulnerable funds were already gone and the attacker's version of the exploit simply reverted.
The label "white-hat front-run" does heavy lifting. Operators behind searcher bots like Yoink are rarely identified, and intercepting stolen assets through a paid auction raises the same liability questions that have hung over sandwich attacks and liquidation sniping for years. Security researchers tracking these events have noted repeatedly that no automated mechanism guarantees intercepted funds reach the original protocol.
How did MEV-Boost make this possible?
Almost none of it happens without Flashbots' MEV-Boost software, which lets Ethereum validators outsource block construction to specialized builders. Adoption now sits at roughly 92 percent of staked validators, meaning the majority of blocks are built by a small set of firms rather than by the validators who ultimately propose them. Searchers submit bundles through private, encrypted channels to those builders, paying for priority placement in a slot.
Flashbots' own MEV-Boost technical documentation and Ethereum's developer resources describe the same tension: separating proposers from builders cut one kind of centralization risk while concentrating power in a handful of builder and relay operators.
How concentrated is Ethereum's relay market?
Relay-monitoring data for a 24-hour window ending August 29, 2026 tracked 11,656 Ethereum blocks built through MEV-Boost relays. The split:
- Ultra Sound Relay: 4,094 blocks (35.1%)
- bloXroute (regulated): 2,771 blocks (23.8%)
- Flashbots Relay: 278 blocks (2.4%)
- Other relays combined: 4,513 blocks (38.7%)
Neutral, non-filtering relays handle roughly 70 percent of daily MEV-Boost block production. Validators route blocks through whichever relay maximizes their payout, compliance features aside, the exact dynamic that let Yoink secure priority placement.
How big is the Ethereum MEV market?
Industry estimates put annual Ethereum MEV extraction at roughly:
- 2024: $1.8 billion
- 2025: $2.2 billion
- 2026: $2.5 billion
The European Securities and Markets Authority, in a July 2025 risk analysis, estimated $561.9 million in Ethereum MEV transaction volume for 2025 using a narrower methodology. Sandwich attacks accounted for about $289.8 million, or 51.56 percent, of that ESMA figure. The gap between billion-dollar industry tallies and ESMA's number reflects how much the final figure depends on what counts as MEV in the first place.
What does this mean for DeFi treasuries?
For protocols holding large multisig treasuries, speed now matters as much as prevention. A configuration error in a Safe 1.3.0 deployment, not a bug in core Safe contracts, is what exposed Kelp DAO's funds. Treasury audits that focus only on smart contract code and skip multisig configuration review are missing a category of risk that this incident makes concrete.
DeFi insurers face murkier economics. When a share of exploited funds gets intercepted by searchers before an insurer or the protocol can respond, payout calculations and recovery timelines shift. September 2026 was already the worst month for crypto hacks this year, totaling $766 million in industry losses, before the Yoink episode added another layer of recovery uncertainty.
Kelp DAO has been here before. Earlier in 2026 the project sued LayerZero Labs over a separate $292 million rsETH exploit, a dispute still working through legal channels. Two major incidents touching the same token in a single year is not a track record investors will shrug off.
What is regulators' exposure?
ESMA's 2025 analysis framed sandwich attacks and extraction activity as a market-structure issue. Yoink's $7.8 million front-run gives that framing a sharper edge: regulators now have a concrete, dollar-denominated example of a bot intercepting stolen assets through a paid auction, with no settled legal pathway for return. Analytics firms including Chainalysis have broadened their monitoring to cover MEV-related transactions alongside traditional hacks, because the line between theft and intercepted theft is no longer clean.
Flashbots' long-term response is SUAVE, a proposed shared, encrypted ordering layer designed to reduce builder concentration across multiple blockchains. Nothing about the Yoink incident suggests SUAVE would have stopped it, but it is the clearest sign that the team running Ethereum's dominant block-building infrastructure treats the current relay market as a problem worth re-architecting. Expect DeFi insurers, multisig providers, and protocol treasuries to harden configuration audits and MEV-aware monitoring before another headline incident forces the issue.
via shattered.io (Original)