ETH Wallet Exploit Seeks $7.7M in rsETH but MEV Bot Intercepts Funds, Kelp Freezes Address

An unidentified attacker exploited a custom module connected to an Ethereum Safe wallet to attempt to steal approximately $7.7 million worth of rsETH. However, an MEV bot named Yoink intercepted the funds before the attacker could seize control. Following the event, the rsETH protocol Kelp temporarily froze the recipient address for 24 hours as a precautionary measure. Meanwhile, minting, withdrawals, and integrations of rsETH continue normally, with no impact reported on Kelp's own contracts.
Details of the Exploit and Attack Methodology
The attacker exploited a public keeper multicall to interact with a custom Uniswap v4 liquidity module connected to the victim’s Ethereum Safe wallet. This custom module had been hooked into a maliciously created pool, allowing the unwrapping of aEthrsETH tokens into rsETH, thus attempting to siphon funds to addresses controlled by the attacker.
Blockchain security firm Blockaid reported that approximately $7.73 million in rsETH was compromised at the time of their initial assessment. The specific Safe wallet owner remains unidentified.
Interception by the MEV Bot Yoink
The exploit attempt was promptly front-run by the MEV bot Yoink—an automated program designed to monitor blockchain transactions for profitable arbitrage or extraction opportunities. The bot captured the rsETH before the attacker could assume control of the stolen assets.
Etherscan data further reveals that Yoink transferred about 18.93 ETH (approximately $46,000) to an address marked as a block builder during the same transaction, highlighting the complex MEV strategies involved.
Kelp Protocol's Response and Impact
Following the incident, the rsETH protocol operator Kelp implemented a 24-hour pause on the recipient address to temporarily restrict token transfers. Kelp emphasized this as a precautionary, wallet-level action only; their own smart contracts remain secure and rsETH remains fully backed.
Kelp confirmed that minting, withdrawals, and integrations continue to operate normally and they are collaborating with security experts to investigate further. The exploited attack vector was related to the custom module linked to the victim’s Safe wallet, with no direct compromise to Kelp’s contracts.
Why it matters
This story highlights the evolving and complex security challenges within the Ethereum ecosystem, particularly involving customized modules and intricate DeFi protocols. At the same time, the successful intervention by an MEV bot illustrates that automated systems can not only profit from front-running strategies but also serve as protectors against malicious actors. Kelp’s swift response to pause the suspicious address underscores the importance of proactive and well-coordinated security measures in DeFi, maintaining user trust and protocol resilience. The incident emphasizes the ongoing need for vigilant monitoring and collaboration among security experts to mitigate risks in the cryptocurrency space.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗