Home Ethereum SKN | Ethereum Wallet Exploit Backfires as MEV Bot Captures $7.7M in rsETH
Ethereum

SKN | Ethereum Wallet Exploit Backfires as MEV Bot Captures $7.7M in rsETH

Share
Share

Key Points:

  • An attacker attempting to exploit a custom module connected to an Ethereum Safe wallet targeted approximately $7.7 million in rsETH, but an MEV bot intercepted the funds first.
  • The bot, known as “Yoink,” captured the rsETH before the original attacker could take control, while transferring about 18.93 ETH worth roughly $46,000 to a block-builder-labeled address.
  • Kelp temporarily froze the receiving wallet for 24 hours, saying the measure was precautionary and that its contracts remained safe and rsETH fully backed.

MEV Bot Front-Runs Ethereum Wallet Exploit

An attempted Ethereum wallet exploit has taken an unusual turn after an automated MEV bot intercepted approximately $7.7 million in rsETH before the original attacker could access the funds.

Blockchain security firm Blockaid said the attacker targeted a Safe wallet belonging to an unidentified user. The apparent attack involved a custom module connected to the wallet rather than a vulnerability in Kelp’s core contracts.

Blockaid initially estimated that approximately $7.73 million in rsETH had been exposed.

The incident demonstrates how the public nature of blockchain transactions can create competing incentives during an exploit. Transactions associated with an attack can be observed by automated systems, allowing MEV bots to identify and act on potentially profitable opportunities before the intended recipient can complete the operation.

Attacker Uses Custom Safe Module

According to Blockaid, the attacker used a public keeper multicall to direct a custom Uniswap v4 liquidity module into a hooked pool created by the attacker.

The process resulted in aEthrsETH being unwrapped into rsETH, creating the assets that the attacker sought to extract.

However, an MEV bot known as Yoink subsequently front-ran the transaction flow.

Yoink is an automated program that monitors blockchain transactions and executes transactions when it identifies potentially profitable opportunities. In this case, the bot captured the rsETH before the original exploiter could take control of the funds.

Blockchain records reviewed through Etherscan also show that Yoink transferred approximately 18.93 ETH, worth around $46,000, to an address labeled as a block builder during the same transaction.

Kelp Freezes Receiving Address

Following the incident, Kelp, the protocol behind rsETH, placed the address that received the funds under a 24-hour pause.

The temporary restriction prevents the tokens at the wallet level from being transferred while the incident is investigated.

Kelp described the action as a precautionary measure and emphasized that its core contracts had not been compromised.

The protocol also said that rsETH remained fully backed and that minting, withdrawals and integrations were continuing normally.

The distinction is important because the apparent attack vector was associated with the custom module connected to the affected Safe wallet rather than Kelp’s own smart contracts.

Security Investigation Continues

The incident remains under investigation, with Kelp working alongside security experts to determine precisely how the custom module was exploited and how the intercepted funds should be handled.

The episode also highlights the increasingly complex dynamics surrounding onchain security. When an exploit transaction becomes visible on a public blockchain, the attacker may face competition from MEV bots, security researchers, white-hat operators and other automated actors capable of interacting with the same funds.

In this case, the intervention prevented the reported $7.7 million in rsETH from immediately reaching the original exploiter, but it also created a separate question over control and recovery of the assets captured by the MEV bot.

Outlook

The Kelp incident underscores the importance of auditing custom wallet modules and understanding the risks created when external components interact with established DeFi infrastructure. The fact that an MEV bot intercepted the funds before the original attacker could complete the exploit illustrates both the transparency and competitive nature of public blockchains. While Kelp maintains that its contracts remain secure and rsETH fully backed, the investigation into the Safe module and the eventual handling of the intercepted assets will determine the final outcome.

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Don't Miss

    SKN | Bitcoin Falls Below $77,000 as Investors Await Inflation Data and Fed Policy Signals

    Key Points: Bitcoin opened at $76,535.95 on Friday, down 2.2% from Thursday’s opening price, before moving to $76,758.63 by 7:23 a.m. ET. Ethereum...

    SKN | Hotter Core CPI Raises Fed Hike Odds, but Markets May Focus on What Higher Rates Signal

    Key Points: U.S. core CPI rose 0.3% in August, above the 0.2% forecast, strengthening expectations for a Federal Reserve rate increase next week....

    Related Articles

    SKN | Anthropic Joins UK FCA AI Sandbox to Support Financial Services Innovation

    Key Points: Anthropic will provide its Claude AI models to organizations participating...

    SKN | Robinhood Chain Surpasses $70 Million in Bridged ETH During First Week

    Key Points • Robinhood Chain attracted more than $70 million in bridged...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY