Tradingview Ethereum Wallet Exploit Results in $7.8 Million Loss Captured by MEV Bot
Article Content
- •An Ethereum wallet lost $7.8 million due to a custom module exploit.
- •MEV bot Yoink intercepted the funds before the attacker could access them.
- •Kelp DAO temporarily paused rsETH transfers to mitigate the impact.
On September 15, 2026, an Ethereum wallet lost approximately $7.8 million in rsETH due to an exploit of a custom Safe module linked to a Uniswap v4 liquidity pool. The attacker utilized a public keeper multicall to redirect the wallet's custom module to a malicious hooked pool, where aEthrsETH was unwrapped into raw rsETH. However, the funds were intercepted by an MEV bot named Yoink before the attacker could access them. The affected wallet was identified by blockchain security firm Blockaid, which reported the loss of $7.73 million in rsETH. Kelp DAO, the protocol behind rsETH, responded by pausing transfers for 24 hours to isolate the affected funds and confirmed that its core contracts were safe. The incident highlights vulnerabilities in custom modules used with Ethereum wallets, emphasizing the need for robust security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Gnosis Safe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…