MEV Bot Intercepts $7.7 Million in rsETH From Exploited Ethereum Safe Wallet
Key Takeaways
- •An attacker exploited a custom Uniswap v4 liquidity module connected to an Ethereum Safe wallet, routing funds through attacker-created hooked pool where aEthrsETH was unwrapped into rsETH.
- •An MEV bot named Yoink front-ran the exploit and seized approximately $7.7 million in rsETH before the original attacker could take control.
- •Etherscan data shows the bot paid roughly 18.93 ETH, valued near $46,000, to an address labeled as a block builder in the same transaction.
- •Kelp placed a 24-hour transfer pause on the address holding the funds, describing the measure as precautionary and confirming that its contracts are safe and rsETH remains fully backed.
- •Minting, withdrawals, and integrations for rsETH are continuing normally as Kelp works with security experts on the investigation, with the pause set to lapse after 24 hours.

An attacker exploited a custom module connected to an Ethereum Safe wallet in an attempt to extract roughly $7.7 million in rsETH, only for the funds to be intercepted by an MEV bot before the exploiter could take control.
According to blockchain security firm Blockaid, the attacker used a public keeper multicall to direct a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where aEthrsETH was unwrapped into rsETH. Blockaid identified the affected wallet as a Safe belonging to an unidentified user and said about $7.73 million in rsETH had been lost at the time of its initial report. (Source: Blockaid)
The attack was then front-run by an MEV bot known as Yoink, an automated program that monitors blockchain transactions for profitable opportunities. Yoink captured the rsETH ahead of the original exploiter, and Etherscan data shows the bot transferred about 18.93 ETH, worth roughly $46,000, to an address labeled as a block builder in the same transaction. (Etherscan) The episode underscores that exploit proceeds are not guaranteed to reach the attacker: bots scanning for the same on-chain opportunity can move first.
MEV, or maximal extractable value, refers to profit that can be captured by reordering, inserting or censoring transactions within a blockchain block. Bots pursuing such opportunities monitor pending transactions and compete to place their own transactions ahead of ones expected to move funds, often paying block builders for favorable placement — the dynamic reflected in Yoink's transfer to the builder-labeled address.
Kelp, the protocol behind rsETH, subsequently placed the address that received the funds under a 24-hour pause, temporarily preventing the tokens from being transferred. "This is a precautionary, wallet-level measure only," Kelp said. "Kelp contracts are safe, rsETH remains fully backed." (Source: KelpDAO)
The protocol said minting, withdrawals and integrations were continuing normally while it worked with security experts to investigate the incident. The apparent attack vector involved the custom module connected to the victim's Safe, while Kelp said its own contracts were unaffected. With the transfer pause set to lapse after 24 hours, the findings of the security review and any further comment from Blockaid or Kelp are the immediate items to watch.
Safe is one of Ethereum's most widely used smart-contract wallet platforms, and rsETH is Kelp's liquid restaking token. Modules are contracts a Safe can enable to execute transactions with the wallet's authority, a capability that makes the modules attached to a wallet a sensitive part of its security setup.
Cointelegraph contacted Blockaid and Kelp for additional comment but had not received a response by publication.
Source: Cointelegraph