A $7.8 million crypto heist was just hijacked by a bot named Yoink | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


An attacker exploited a Gnosis Safe wallet on Ethereum, removing about 2,900 rsETH, worth roughly $7.8 million, on Tuesday.

An automated bot known as “yoink” front-ran the attack transaction and extracted the tokens, security firms BlockSec, Blockaid and SlowMist said.

The victim’s wallet was set up to let a helper contract move money for it, an ordinary arrangement for people who automate their trading. The helper was meant to verify that the caller had permission, but SlowMist and BlockSec found the check approved anyone who named the helper itself as the target.

The attacker then dumped around 2,900 rsETH into a trading pool built minutes earlier around a worthless token called Permissionless Attacker Token, leaving the wallet with a receipt worth nothing. Yoink’s bot paid roughly $47,000 to jump the queue and took the tokens, sending 2,882 rsETH to a separate address.



Click Here For The Original Source.

——————————————————–

..........

.

.