MEV Bot Intercepts $7.73 Million Withdrawal from Safe Wallet

In Crypto Regulations
September 16, 2026

MEV Bot Intercepts $7.73 Million Withdrawal from Safe Wallet

On September 15, an unknown attacker targeted a Safe wallet on the Ethereum network, initiating the withdrawal of approximately 2900 rsETH, valued at around $7.73 million. The transaction was detected by the MEV bot Yoink, which executed its own operation before the attacker and seized the assets, according to Blockaid specialists.

According to the company, the attacker used a public Multicall invocation, designed for automatic operations, to redirect a user-connected Uniswap v4 liquidity module to a pool created with a malicious smart contract.

This contract unwrapped aEthrsETH back into rsETH, after which Yoink extracted the assets in the same block using MEV. One of the transactions can be tracked via Etherscan.

Where the Error Occurred

Experts from BlockSec and SlowMist linked the incident to an authorization check error in an auxiliary Multicall contract, which the wallet owner had previously authorized. Due to incorrect parameter checks, an external user could gain authorization and initiate operations through the trusted component.

AstraSec also identified the flawed authorization check in the Multicall contract as the cause of the incident.

Researchers concluded that the issue did not affect the core Safe smart contracts. The vulnerability was in an additional component connected by the specific wallet owner.

Kelp Temporarily Restricts Operations for Address

The Kelp DAO protocol, which issues rsETH, detected suspicious activity on one of the addresses that received tokens and temporarily restricted operations for 24 hours.

Kelp emphasized that the restriction applies only to one address. The protocol’s smart contracts remain unaffected, rsETH is fully backed, and issuance, withdrawals, and integrations continue to operate normally. Users do not need to take any additional actions.

In February 2025, a vulnerability in the Safe infrastructure was cited as the main cause of the Bybit crypto exchange hack.

Avatar photo
/ Published posts: 1088

Steven M. Crimmins is a cryptocurrency strategist and freelance writer who has followed the blockchain industry since Bitcoin’s early days. Known for his sharp analysis of altcoins and trading strategies, Steven provides Satoshi News Africa readers with market-focused content grounded in research. He is especially interested in how African traders are adopting crypto as an alternative to traditional markets. Steven is also a podcast host, where he discusses emerging technologies and investment trends.