MEV Bot Front-Runs $7.8M Exploit to Intercept 2,882 rsETH From Flawed Multicall Contract

AI مارکیٹ کا خلاصہ
An attacker exploited a permission-validation flaw in a Multicall contract authorized by a Safe multisig, targeting ~2,900 rsETH, but a MEV bot frontran the transaction and intercepted 2,882 rsETH after paying ~$47k in gas. Security firms indicate the issue came from user-authorized components rather than Safe's core contracts. Kelp DAO paused the receiving address for 24 hours, highlighting ongoing smart-contract and mempool risks.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT+0.64%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
● Neutral
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Huo Xing Cai Jing, citing reporting from CoinDesk, stated that an attacker exploited an access-control permission vulnerability within a custom Multicall contract authorized through a Safe multisignature wallet in an attempt to drain approximately 2,900 rsETH, valued at roughly $7.8 million. An automated MEV bot known as "yoink" detected the malicious transaction in the public Ethereum mempool and paid approximately $47,000 in priority gas fees to front-run the execution, successfully capturing 2,882 rsETH before transferring the capital to a secondary holding address. Blockchain security intelligence firms BlockSec, Blockaid, SlowMist, and AstraSec confirmed that their forensic analyses trace the root cause to user-authorized external components rather than vulnerabilities within Safe's core smart contract codebase. Kelp DAO, the issuer of the liquid restaked token rsETH, has enacted an emergency 24-hour freeze on the recipient address while coordination efforts continue.