ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address

An attacker exploited a custom module on an Ethereum Safe wallet to strip about $7.73 million in rsETH, but an MEV bot named Yoink front‑ran the transaction and captured the tokens. Kelp, the protocol behind rsETH, then placed the receiving address on a 24‑hour pause while stating its contracts were unaffected and rsETH remained fully backed.

By AI NewsroomPublished about 1 hour agoUpdated about 1 hour ago0 views
ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address

Why It Matters

The incident highlights how MEV bots can intercede in on‑chain thefts, sometimes seizing funds before an exploiter can move them, and it underscores the operational steps protocols may take to limit downstream movement of intercepted assets while investigations proceed.

Key Facts

  • victim wallet: An Ethereum Safe belonging to an unidentified user
  • stolen amount: $7.73 million in rsETH (as reported by Blockaid)
  • exploit method: Public keeper multicall directing a custom Uniswap v4 liquidity module into an attacker-created hooked pool; aEthrsETH unwrapped into rsETH
  • mev bot: Yoink
  • yoink transfer: About 18.93 ETH (~$46,000) sent to an address labeled as a block builder in the same transaction

Security firm Blockaid reported that an attacker abused a custom module connected to an Ethereum Safe to extract roughly $7.73 million in rsETH. The exploit reportedly used a public keeper multicall to steer a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where aEthrsETH was converted into rsETH and removed from the Safe.

Before the original exploiter could take full control of the funds, an MEV bot called Yoink detected and front‑ran the transaction, intercepting the rsETH. On‑chain data reviewed on Etherscan shows Yoink moved about 18.93 ETH (approximately $46,000) to an address that is labeled as a block builder within the same transaction.

In response, Kelp — the team behind rsETH — placed the address that received the tokens under a 24‑hour pause to temporarily block further transfers at the wallet level. Kelp said its contracts were not impacted, that rsETH remained fully backed, and that minting, withdrawals and integrations were continuing as normal while it coordinated with security specialists to investigate the incident.

Blockaid identified the affected account as a Safe owned by an unnamed user. Cointelegraph contacted Blockaid and Kelp for additional comment but had not received replies by the time of publication.

Keep Reading