Crypto News

MEV bot intercepts $7.7M in rsETH from Ethereum wallet exploit

Sep 16, 2026 00:44 ethereum mev-bot safe-wallet kelp rsETH
MEV bot intercepts $7.7M in rsETH from Ethereum wallet exploit

MEV bot fronts $7.7M exploit on Ethereum

Blockchain security firm Blockaid reported that an attacker attempted to steal roughly $7.73 million in rsETH from a specific Ethereum Safe wallet. The exploit targeted a custom module connected to the victim's wallet. Before the attacker could complete the theft, an automated MEV bot known as "Yoink" intercepted the transaction.

MEV stands for Maximal Extractable Value, a practice where bots monitor blockchain activity to capture small profits by reordering transactions. In this case, the bot successfully captured the stolen assets before the original exploiter could move them.

Key details from the incident

  • The attack used a public keeper multicall to direct a custom Uniswap v4 liquidity module.
  • The attacker aimed to move aEthrsETH into a hooked pool to unwrap it into rsETH.
  • The MEV bot transferred about 18.93 ETH, worth roughly $46,000, to a block builder address during the same transaction.
  • Kelp, the protocol behind rsETH, placed the receiving address under a 24-hour pause.

Kelp confirms wallet-level precaution

Kelp stated that the pause is a precautionary, wallet-level measure only. The protocol emphasized that its core contracts remain safe and that rsETH is still fully backed. According to Kelp, normal minting, withdrawals, and integrations continued during the incident. The company is currently working with security experts to investigate the exploit vector, which appears to have been isolated to the victim's custom module rather than Kelp's own smart contracts.

What is confirmed

It is confirmed that approximately $7.73 million in rsETH was involved in the exploit attempt on a Safe wallet belonging to an unidentified user. It is also confirmed that an MEV bot intercepted these funds and that Kelp applied a 24-hour freeze to the address holding the tokens. Etherscan data supports the movement of 18.93 ETH associated with the bot's activity.

Why this matters for wallet security

This incident highlights the risks associated with using third-party or custom modules with multi-sig wallets like Safe. While the MEV bot prevented the initial loss for the victim, it also demonstrates how quickly automated programs can react to public blockchain transactions. Users relying on complex DeFi strategies through custom hooks may face greater risk from smart contract vulnerabilities compared to standard wallet usage.

Looking ahead

Kelp has not specified when the 24-hour pause will end or what will happen to the intercepted funds. The protocol is continuing its investigation with security experts to determine the full scope of the vulnerability in the custom module.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!