EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

MEV机器人抢先执行以太坊上780万美元rsETH漏洞利用

2026-09-17 08:30:39
Bookmark

MEV机器人Yoink抢先执行rsETH漏洞事件,涉及金额约780万美元

链上数据和安全研究人员显示,2026年9月15日,一个名为Yoink的MEV(最大可提取价值)机器人抢跑了一起据报道针对rsETH的攻击。在原始攻击交易执行之前,该机器人从Aave中撤出了近2,900枚rsETH,当时价值约为780万美元。

关键要点

MEV机器人Yoink抢跑了据报道针对rsETH的攻击,于2026年9月15日在以太坊区块25980525中以位置零落地。

Etherscan记录显示,该机器人从Aave撤出了2,899.99枚rsETH(价值7,476,833.83美元),随后将2,882.37枚rsETH(价值7,431,373.16美元)转发至外部地址。

目前没有任何第一方声明证实接收地址的最终控制者及Safe钱包所有者的身份。

rsETH是以太坊上发行的流动性质押代币,代表通过质押协议获取额外收益的已质押ETH头寸。它与Aave等借贷市场的深度集成意味着大型头寸可以通过智能合约调用进行提取或清算,这使其成为MEV机器人积极监控公共内存池的目标。

交易序列分析

根据Etherscan对区块25980525的记录,Yoink的交易于2026年9月15日UTC时间04:38:47执行。该机器人从Aave撤出了2,899.999999999997756819枚rsETH,执行时价值为7,476,833.83美元。随后,Yoink将2,882.37枚rsETH(价值7,431,373.16美元)转发至地址0xC70f00CD7E461686b04B0E912E309becA8b80ea0。现有证据尚未确立该接收地址的身份及其最终控制者。

The Defiant报道指出,Yoink与原始攻击交易落入同一个以太坊区块,其中Yoink占据位置零,而原始攻击者的交易 reverted(回滚)。实现区块位置零需要提交具有更高优先费用的交易或使用私有中继,这是专业MEV运营商常用的技术。

未确认事项

安全公司Blockaid表示,其漏洞检测系统标记了以太坊上一个不明用户Safe钱包发生的漏洞,报告称约有773万美元的rsETH损失得到确认。Blockaid并未公开命名Safe所有者。

多份次要报告将受影响的Safe归因于Kelp DAO,并声称该协议冻结了相关资金。但在现有证据中,未验证来自Kelp DAO、Safe、Aave或钱包所有者的任何第一方声明。这些主张应被视为未经证实。

此次rsETH漏洞对DeFi用户和协议的意义

公共内存池中的执行风险

This incident illustrates a structural strain in the Ethereum public memory pool: any transaction broadcast without a private relay infrastructure is visible to the MEV robot before being included in the block. In a DeFi security incident, this situation has a dual impact. While the robot rush vulnerability may prevent a designated attacker from capturing funds, the robot itself retains the proceeds rather than returning them to affected parties.

The result-approximately $7.4 million was transferred to an address of unknown ownership-reflects a pattern seen in the early DeFi incident. Similarly, the DeFi Bridge vulnerability involving counterfeit BTC tokens also demonstrated how unauthorized flows of funds can cascade through interconnected protocol levels before any manual response.

Protocol security lessons

The use of Safe multi-signature wallets as obvious victims is noteworthy. Safe is widely deployed by DAO and institutional DeFi participants precisely because it requires multiple signers. Attacks on Safe indicate either a compromised signer key, a malicious transaction approved by a quorum, or a module vulnerability rather than a simple private key disclosure.

Aave serves as the liquidity layer for rsETH extraction, pointing out the compounding risk of using liquid pledge tokens as collateral in lending markets. A position size sufficient to generate $7.4 million in a single withdrawal is essentially a MEV target, regardless of whether the trigger trade is a bug or a routine liquidation. Protocol teams that are evaluating similar collateral risks on other chains face similar memory pool exposure risks.

链上归因的局限性

截至发布时,以太坊交易价格为2,412.37美元,24小时内上涨0.14%,更广泛的加密货币市场情绪指数为51(中性)。宏观背景并未放大rsETH或ETH价格的即时影响。

链上数据可以确认资金流向、时间和地址,但在没有链下披露的情况下,无法确认意图、协议归属或资金追回。直到Safe所有者、涉及的Kelp DAO或接收地址的控制者发布声明,这笔约740万美元rsETH的最终处置仍是以太坊DeFi生态系统的一个悬而未决的问题。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP