Finst

Yoink Bot Steals $7.8 Million From Gnosis Safe Wallet

Security firms point to a flaw in a trusted helper contract, not in Safe’s core. Kelp DAO says rsETH remains backed, and the attack was also beaten by a frontrunning bot.

Yoink Bot Steals $7.8 Million From Gnosis Safe Wallet

Key Takeaways

  • An attacker took about 2,900 rsETH, worth $7.8 million, from a Gnosis Safe wallet on Ethereum.
  • The transaction was front-run by the Yoink bot, which paid about $47,000 and sent 2,882 rsETH to another address.
  • The flaw was in an authorization check in a trusted helper and Multicall contract, not in Safe’s core contracts.

An attacker on Ethereum removed about 2,900 rsETH, worth around $7.8 million (€6.8 million), from a Gnosis Safe wallet. According to security firms BlockSec, Blockaid, and SlowMist, the attack was then front-run by a bot called Yoink, which front-ran the transaction and sent the tokens to another address.

How The Attack Worked

The wallet was set up so that a helper contract was allowed to move funds, a setup that is common among people who automate their trading. According to SlowMist and BlockSec, that helper was supposed to check whether the caller had permission, but that check ended up approving anyone the helper itself pointed to as the target.

The attacker then swapped about 2,900 rsETH in a trading pool that had been set up just minutes earlier around a worthless token called Permissionless Attacker Token. That left the wallet with a receipt that was worth nothing. According to the security firms, Yoink paid about $47,000 (€40,700) to get priority and ultimately took 2,882 rsETH to a separate address.

Flaw Was In A Trusted Component

AstraSec wrote on X that the core issue was a faulty authorization check in the Multicall contract. Other security firms reached the same conclusion: the flaw was in a component the wallet owner had trusted, not in Safe’s core contracts.

That distinction matters because many crypto users turn on extra features through wallets and helper contracts for trading or automation. A previous study of dozens of major smart contract attacks already showed that successful exploits often are not just about a technical bug, but also about human choices and weak assumptions around usage and permission. The shift toward key and governance attacks also shows that attackers are increasingly targeting the weakest link around access and control, not just the code itself.

Why This Matters For Users

Kelp DAO, the issuer of rsETH, said its contracts are secure and that rsETH is fully backed. The company also said it temporarily paused an address that had received rsETH a few hours earlier for 24 hours, so the token cannot move in or out there.

For European crypto users, this incident shows that risks do not only sit inside a protocol itself, but also in the extra layers around it, like helper contracts and automated trading. Especially with wallets that combine multiple functions, a small mistake in access control can be enough to cause a big loss.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.