Hacker loses $7.73M to MEV bot in rsETH Safe module exploit
On September 15, 2026, an attacker found a vulnerability in a custom router module of a Gnosis Safe holding over $7.73 million in wrapped rsETH from Aave. The exploit was sent to the mempool, but MEV bot Yoink copied and executed the transaction first, with the attacker arriving an hour later for leftovers.
- Vulnerability found in custom Gnosis Safe router module with $7.73M rsETH
- MEV bot Yoink intercepted the mempool transaction and executed it first
- Router source code unpublished; flaw reconstructed from SlowMist bytecode
- Exploit author arrived an hour later and collected only remaining funds
Read next
Security