On September 15, 2026, an automated trading program did something most exchange-listed companies would get sued for: it watched a theft happen in real time, copied the attacker’s exact method, and grabbed the money first. The bot, known on-chain as Yoink, intercepted roughly $7.8 million in rsETH, Kelp DAO’s liquid restaking token, moments after a hacker attempted to drain the same funds from a misconfigured Safe wallet. Yoink paid about 18.93 ETH, close to $46,000, to an Ethereum block builder to guarantee its transaction landed first. The attacker got nothing. Whether Kelp DAO or its users got anything back is still an open question.
The incident is a clean, almost clinical example of what crypto engineers call MEV, or maximal extractable value: the profit a block producer or a well-positioned bot can squeeze out of the order in which transactions get processed. MEV has existed since Ethereum’s early arbitrage days, but the Yoink episode pushes it somewhere new. A bot didn’t just reorder trades for profit. It raced a criminal to the finish line using the criminal’s own exploit code, then paid cash to a block builder to win. It’s the latest entry in a run of cryptocurrency security incidents that have made 2026 a rough year for anyone holding assets in a shared wallet.
What happened: inside the Yoink front-run
The target was a Safe multisig wallet, built on the widely used Safe 1.3.0 contract version, holding close to 2,900 rsETH. An attacker found a configuration flaw in the wallet’s signing setup and crafted a transaction to drain it. Before that transaction got mined, Yoink spotted it sitting in the public mempool, copied its logic, and submitted a competing bundle with a higher payment to the block builder assembling that slot.
Block builders accept the highest-paying valid bundle, not the first one submitted. That rule is what let Yoink win. By offering roughly $46,000 in builder payment, the bot made its version of the drain transaction more profitable to include than the attacker’s, so the builder packed Yoink’s transaction into the block instead. The attacker’s copy of the exploit simply failed once the vulnerable funds were already gone.
This is sometimes called a white-hat front-run, but the label does a lot of work. Security researchers who track these events note that the operators behind bots like Yoink are rarely identified, and there’s no guarantee intercepted funds get returned to the original owner. Kelp DAO’s token has been through this before: the project sued LayerZero Labs over a separate $292 million rsETH exploit earlier in 2026, a dispute that is still working through legal channels. Two major incidents touching the same token in one year is not a coincidence investors are likely to shrug off.
How MEV bots turn exploits into a race
MEV bots, known in the industry as searchers, run constant scans of Ethereum’s public mempool looking for profitable patterns: arbitrage across decentralized exchanges, liquidations, and increasingly, in-progress exploits. When a searcher spots an attacker’s transaction sitting unconfirmed, it can simulate the same call, verify the payout, and submit its own version through a private channel straight to a block builder.
The mechanics look something like this in simplified form:
// simplified searcher logic, not production code
mempool.onPendingTx((tx) => {
if (isExploitPattern(tx) && simulate(tx).profit > gasAndBuilderFee) {
const bundle = cloneExploit(tx, myAddress);
const bid = estimateMinWinningBid(tx);
submitPrivateBundle(builderEndpoint, bundle, bid);
}
});
What makes this possible at scale is the private order flow that platforms like Flashbots built after Ethereum’s move to proof of stake. Searchers no longer have to broadcast their intentions publicly and risk getting front-run themselves, they can send bundles directly to a builder through an encrypted relay. That infrastructure, originally sold as a way to cut down on failed transactions and gas waste, now routinely decides who keeps the proceeds of a hack.
MEV by the numbers: a market bigger than most people realize
Estimates of Ethereum’s annual MEV extraction have climbed steadily. Industry trackers pegged the figure at roughly $1.8 billion in 2024, $2.2 billion in 2025, and close to $2.5 billion in 2026. These are aggregated estimates pulled from dashboards like libMEV and Flashbots’ own data, not a single official Ethereum statistic, and they measure slightly different things depending on the source: some count builder payments, others count total value moved through MEV-related transactions.
| Year | Estimated Annual Ethereum MEV | Primary Driver |
|---|---|---|
| 2024 | ~$1.8 billion | Arbitrage and liquidations |
| 2025 | ~$2.2 billion | Sandwich attacks, DEX arbitrage |
| 2026 | ~$2.5 billion | Arbitrage, liquidations, exploit front-running |
A separate European Securities and Markets Authority risk analysis, published in July 2025, estimated around $561.9 million in Ethereum MEV transaction volume during 2025 using its own narrower methodology, with sandwich attacks accounting for 51.56 percent, or about $289.8 million, of that figure. The gap between that number and the billion-dollar industry estimates shows how much the final figure depends on what counts as MEV in the first place. None of these datasets should be read as directly comparable to each other.
Flashbots, MEV-Boost, and the infrastructure running the show
Almost none of this happens without Flashbots’ MEV-Boost software, which lets Ethereum validators outsource block construction to specialized builders instead of assembling blocks themselves. This proposer-builder separation model is designed to stop validators from running their own extraction schemes and to spread MEV revenue more evenly. In practice, MEV-Boost adoption is now estimated at about 92 percent of Ethereum’s staked validators, meaning the overwhelming majority of blocks are built by a small set of specialized firms rather than by the validators who ultimately propose them.
Flashbots documents the proposer-builder split in detail in its MEV-Boost technical documentation, and Ethereum’s own developer resources describe the broader MEV problem in its MEV overview. Both frame the same tension: separating proposers from builders reduced one kind of centralization risk, at the cost of concentrating power in a handful of builder and relay operators.
SUAVE and the push toward private, cross-chain ordering
Flashbots’ long-term answer to that concentration is SUAVE, short for Single Unifying Auction for Value Expression, detailed on the team’s research blog. SUAVE is designed as a shared, encrypted mempool and auction layer that multiple blockchains could plug into, so that transaction ordering happens through a neutral, privacy-preserving auction instead of whichever builder happens to dominate a given chain. It’s still early infrastructure, and nothing about the Yoink incident suggests SUAVE would have stopped it, but it’s the clearest sign that Flashbots itself sees the current builder market as a problem worth re-architecting.
Relay concentration: who actually builds Ethereum’s blocks
Relay-monitoring data for a 24-hour window ending August 29, 2026 tracked 11,656 Ethereum blocks built through MEV-Boost relays. The split between relay operators shows just how concentrated the builder market has become, even years after proposer-builder separation was supposed to decentralize it.
| Relay | Blocks Built (24h, Aug 29, 2026) | Share |
|---|---|---|
| Ultra Sound Relay | 4,094 | 35.1% |
| bloXroute (regulated) | 2,771 | 23.8% |
| Flashbots Relay | 278 | 2.4% |
| Other relays (combined) | 4,513 | 38.7% |
Neutral, non-filtering relays now handle roughly 70 percent of daily MEV-Boost block production, while relays built around sanctions screening have shrunk to a much smaller share of the market. That shift matters for a reason that has nothing to do with Yoink directly: it signals that validators increasingly route blocks through whichever relay maximizes their payout, compliance features aside, which is exactly the dynamic that let a bot like Yoink get prioritized placement in the first place.
White-hat rescue or opportunistic extraction?
The framing around Yoink split crypto Twitter almost instantly. One camp calls this a public good: a bot that beats criminals to stolen funds using nothing but faster code and a bigger builder payment, arguably protecting users better than any audit could have. The other camp points out that nobody knows who controls Yoink, whether the $7.8 million will ever reach Kelp DAO or its token holders, or whether this is simply a more polite-sounding version of the same extraction that sandwich bots run on ordinary traders every day.
Both things can be true. A bot racing to secure funds ahead of a confirmed bad actor is, mechanically, a defensive move. But paying a builder to win that race is the exact same transaction-ordering market that produces sandwich attacks and liquidation sniping on a daily basis. The tool is neutral. What it gets used for depends entirely on who’s running it, and in this case, that’s unknown. It echoes a question the industry already faced after the Magic Eden marketplace exploit earlier this year, where responders managed to save $5.7 million in NFTs against $2.8 million actually stolen: a good recovery number doesn’t always mean a good actor did the recovering.
The Safe wallet problem behind the headline
Safe, formerly Gnosis Safe, is the most widely used multisig wallet standard in crypto, securing treasuries for DAOs, funds, and protocols across the Ethereum ecosystem. A configuration flaw in a Safe 1.3.0 deployment, not a bug in the core Safe contracts themselves, is what exposed Kelp DAO’s funds in this case. That distinction matters for the rest of the industry: this wasn’t a zero-day in Safe’s code, it was a setup mistake, which means any team running an older or misconfigured Safe instance could be sitting on the same exposure right now.
Treasury security audits that focus only on smart contract code and skip multisig configuration review are, by this incident’s own evidence, missing an entire category of risk. Expect DeFi insurers and auditors to add configuration checks to their standard scope in the coming months, the same way protocols moving assets across chains have had to adopt dedicated Foundry-based exploit testing after a string of bridge hacks.
Historical context: from sandwich bots to exploit racing
MEV entered the crypto vocabulary around 2019, when Flashbots and a handful of researchers started documenting how miners, and later validators, could profit from reordering transactions. Early MEV was almost entirely arbitrage: bots buying and selling the same asset across decentralized exchanges within a single block. Sandwich attacks followed, where a bot buys ahead of a known pending trade and sells right after, pocketing the price movement at the trader’s expense.
Ethereum’s switch to proof of stake in September 2022 reshaped the market again by introducing proposer-builder separation, which is how MEV-Boost became dominant. What the Yoink incident adds to that timeline is a new category entirely: bots that treat live exploits as just another arbitrage opportunity, racing attackers instead of ordinary traders. It’s the same market structure, aimed at a new kind of target.
A pattern of bots losing money too
MEV bots aren’t invincible. Earlier in 2026, the bot associated with the well-known address jaredfromsubway.eth reportedly lost around $7.5 million after an attacker fed it fake trading opportunities designed to trigger a flawed execution path. That incident is a useful reminder that the same aggressive, automated logic that let Yoink win can just as easily be turned against a searcher by anyone who understands how it hunts for profit.
Market impact: what this means for DeFi protocols
For protocols holding large treasuries in multisig wallets, the immediate takeaway is that speed now matters as much as prevention. Even a well-designed Safe setup can be drained if a single configuration error slips through, and once a malicious transaction hits the public mempool, the race to control the outcome moves to whoever can pay a builder the most, the fastest. That increasingly favors protocols and insurers that run their own MEV-aware monitoring rather than relying on the goodwill of an anonymous rescue bot.
It also complicates the economics of DeFi insurance. If a share of exploited funds gets intercepted by searchers before an insurer or the protocol itself can respond, payout calculations and recovery timelines get murkier. The worst month for crypto hacks so far this year, September, which totaled $766 million in losses across the industry, already strained that model before Yoink entered the picture.
Competitive landscape: how other chains handle MEV differently
Ethereum’s open, public mempool and permissionless builder market make it uniquely exposed to this kind of exploit racing. Other ecosystems have taken different paths. Solana’s Jito client bundles MEV extraction directly into its validator client rather than relying on an external proposer-builder split, giving the network more centralized control over how bundles get prioritized. Several Cosmos-based chains have experimented with encrypted transaction pools specifically to stop searchers from seeing pending transactions before they’re final, which would make a Yoink-style front-run structurally harder to pull off.
Ethereum’s own layer-2 networks mostly inherit the base chain’s MEV dynamics today, though several are exploring their own sequencing rules. The broader pattern across the industry is clear: every chain that wants fast, permissionless execution ends up facing some version of the same ordering problem Ethereum has, it’s just a matter of how transparent and how automated the extraction becomes.
The regulatory angle: Europe is already watching
The European Securities and Markets Authority has already published risk analysis specifically on Ethereum MEV, framing sandwich attacks and extraction activity as a market-structure issue worth regulatory attention. Incidents like Yoink’s $7.8 million front-run give that analysis a sharper edge: regulators now have a concrete, dollar-denominated example of a bot effectively intercepting stolen assets through a paid auction, raising questions about who’s liable if those funds never get returned to their rightful owner.
Analytics firms that track illicit crypto flows, including Chainalysis, have broadened their monitoring in recent years to cover MEV-related transactions alongside traditional hacks and scams, since the line between a theft and a theft that got intercepted is no longer as clean as it used to be. That same blurring shows up in oracle-driven DeFi exploits, like the incident that drained $3.5 million from Nostra Finance after Pragma’s price feeds misfired on Starknet, where the question of who’s a thief and who’s a rescuer got just as murky.
5 predictions for where MEV goes from here
- More exploit-racing bots will emerge in 2027 as searchers realize live hacks are a profitable niche, blurring the line between rescue and theft even further.
- Regulatory scrutiny will spread beyond Europe, with other financial regulators likely producing their own MEV risk assessments once a few more headline incidents like Yoink’s land.
- Safe and other multisig providers will push harder on configuration audits and default hardening, treating setup errors as seriously as contract bugs.
- SUAVE-style shared ordering layers will see renewed interest from protocols that want to reduce reliance on a handful of dominant relays like Ultra Sound and bloXroute.
- DeFi insurers will start pricing MEV-related recovery uncertainty into premiums, rather than treating a hack and its outcome as a single, predictable event.
Frequently asked questions
What is MEV in cryptocurrency?
MEV, or maximal extractable value, is the profit a validator, block builder, or bot can capture by controlling the order in which transactions get included in a block. It covers everything from simple arbitrage to sandwich attacks and, as the Yoink incident shows, racing to intercept an in-progress exploit.
Who or what is the MEV bot Yoink?
Yoink is the on-chain name of an automated searcher bot that, on September 15, 2026, intercepted about $7.8 million in rsETH from a vulnerable Safe wallet before the original attacker’s transaction could confirm. Its operator has not been publicly identified.
What is Kelp DAO’s rsETH?
rsETH is Kelp DAO’s liquid restaking token, which represents staked and restaked ether that remains usable in other DeFi protocols. The token has now been tied to two major 2026 incidents: this Safe wallet exploit and an earlier, unrelated $292 million exploit that led Kelp DAO to sue LayerZero Labs.
Is front-running a hacker to grab the funds first legal?
There’s no settled legal answer. Taking assets that don’t belong to you, even from a thief, isn’t automatically lawful just because the original attempt was criminal. Regulators including ESMA have flagged MEV broadly as a market-structure concern, but no enforcement action has specifically targeted an exploit-racing bot like Yoink as of this writing.
What is MEV-Boost and why does it matter here?
MEV-Boost is Flashbots’ software that lets Ethereum validators outsource block construction to external builders, now used by roughly 92 percent of staked validators. It’s the infrastructure that let Yoink pay a builder directly for priority placement instead of relying on luck in the public mempool.
How much money does MEV extract from Ethereum every year?
Industry estimates put 2026 Ethereum MEV extraction at roughly $2.5 billion, up from about $2.2 billion in 2025 and $1.8 billion in 2024. A separate, narrower ESMA analysis estimated $561.9 million in MEV transaction volume for 2025 alone, using different methodology, so the two sets of figures shouldn’t be compared directly.
Can regular crypto users protect themselves from MEV?
Using wallets and DEX front-ends with built-in MEV protection, setting tighter slippage limits, and routing trades through private transaction relays all reduce exposure to sandwich attacks. None of that would have stopped the Yoink incident, which targeted a protocol treasury rather than an individual trade.
What is SUAVE and is it related to this incident?
SUAVE is Flashbots’ proposed shared, encrypted ordering layer meant to reduce builder concentration across multiple blockchains. It wasn’t involved in the Yoink incident, but it represents the clearest industry attempt so far to redesign the system that made this kind of exploit race possible in the first place.




