Crypto news report · source clearly identified

MEV Bot Intercepts $7.7 M rsETH Exploit, Kelp Pauses Affected Address

An attacker tried to steal about $7.7 million in rsETH from a custom Safe module, but an MEV bot front‑ran the transaction and captured the funds. Kelp then froze the receiving address for 24 hours.

An attacker targeting a custom module linked to an Ethereum Safe wallet attempted to extract roughly $7.73 million worth of rsETH. The exploit was intercepted by an MEV bot known as “Yoink,” which front‑ran the transaction and seized the stolen tokens.

Exploit Mechanics

According to blockchain security firm Blockaid, the attacker used a public keeper multicall to route a custom Uniswap v4 liquidity module into a pool they had created. The pool unwrapped aEthrsETH into rsETH, moving the value into the attacker’s address.

MEV Bot Intervention

The Yoink bot monitors pending transactions for profitable opportunities. It detected the pending exploit and submitted a competing transaction that captured the rsETH before the attacker could complete the withdrawal. Etherscan data shows Yoink transferred about 18.93 ETH (≈ $46 k) to an address identified as a block builder within the same transaction.

Kelp’s Response

Kelp, the protocol behind rsETH, placed a 24‑hour pause on the address that received the Yoink‑captured funds, preventing further transfers. Kelp emphasized that the pause is a wallet‑level precaution, that its contracts remain safe, and that rsETH stays fully backed.

Current Status

Minting, withdrawals, and integrations on Kelp continue as the team works with security experts to investigate the incident. The affected Safe wallet belongs to an unidentified user, and no further details have been provided by Blockaid or Kelp at the time of publication.

Source & attribution

News Source

Publisher
Cointelegraph
Original date
September 15, 2026, 3:21 PM
Original headline
ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address
View original report ↗