What happened?
According to a report from The Defiant, an exploit attempt targeting a Safe-type wallet occurred on Ethereum on Tuesday. But before the attacker could make off with the loot, the transaction was front-run by a so-called MEV bot labeled Yoink.
Blockchain security firm PeckShield described the event as an exploit in the liquid staking token rsETH worth approximately $7.81 million. Onchain records cited by The Defiant show that Yoink's transaction received 2,900 rsETH and forwarded 2,882.37 rsETH.
What do the key terms mean?
For this episode to make sense, a few terms need clarifying:
- MEV (Maximal Extractable Value): the value that can be captured by reordering, inserting, or removing transactions in a block. Bots hunt for this value automatically.
- Front-running: a bot spots a pending transaction in the mempool (the queue of unconfirmed transactions) and inserts its own transaction ahead of it with a higher fee so that it executes first.
- rsETH: a liquid restaking token that represents a claim on staked ETH.
- Safe wallet: a multisig wallet (requiring multiple signatures), commonly used by projects and teams to manage funds.
How exactly did the bot front-run the attack?
The detailed mechanics, namely why the Safe wallet was vulnerable and exactly how Yoink intercepted and front-ran the transaction, are not spelled out step by step in the published sources. What is documented onchain are the token movements: the bot received 2,900 rsETH and forwarded 2,882.37 rsETH. The difference (roughly 17.63 rsETH) is consistent with how this type of bot typically keeps a portion of the loot, but the sources do not confirm the exact purpose of that difference.
In practice, with so-called "whitehat" or incidental front-runs, it happens that a bot captures the funds before the attacker does. Whether this was a rescue of funds or simply another actor diverting the loot for itself is not clear from the sources.
What is still unknown?
In short, quite a lot:
- Who was behind the original exploit. The attacker's identity is not confirmed.
- Who operates Yoink and what its intent was.
- Where the funds will ultimately end up and whether they will be returned to the original owner.
- The specific vulnerability that exposed the Safe wallet to attack.
These are precisely the questions that, after incidents like this, are usually answered later by follow-up analysis from security firms or a statement from the affected project.
What to watch for with this type of event?
The case is a textbook example of how Ethereum's mempool works as a public space: pending transactions are visible and bots actively monitor them. When a valuable exploit surfaces around a protocol or wallet, it is not unusual for a third party to step in and divert the loot before the original attacker.
When it comes to figures around incidents like this, one rule applies: the initial damage estimate (here $7.81 million according to PeckShield) may be refined once the full scope of the movements and the market value of the affected tokens at the moment of the attack are traced. charliedesk will track this figure and the fate of the funds, and will correct it if later onchain data paints a different picture.

