The $7.7M Ethereum Exploit Was Beaten by an MEV Bot

An attacker targeting a custom module connected to an Ethereum Safe wallet lost control of roughly $7.7 million in rsETH after the MEV bot Yoink front-ran the transaction. Kelp later paused the receiving address for 24 hours.

An attempted exploit involving an Ethereum Safe wallet ended with the stolen funds intercepted by an MEV bot rather than secured by the attacker. The incident involved roughly $7.7 million in rsETH, a token issued by Kelp.

Custom module redirected funds

According to blockchain security firm Blockaid, the attacker used a public keeper multicall to route a custom Uniswap v4 liquidity module into an attacker-created hooked pool. That process unwrapped aEthrsETH into rsETH.

Blockaid identified the affected wallet as a Safe belonging to an unidentified user. Its initial report estimated that approximately $7.73 million in rsETH had been lost.

Yoink front-ran the exploit

Before the original exploiter could take control of the assets, an MEV bot known as Yoink front-ran the transaction and captured the rsETH. MEV bots monitor blockchain activity for transactions that may offer profitable execution opportunities.

Etherscan data cited in the report shows that Yoink transferred about 18.93 ETH, worth roughly $46,000, to an address labeled as a block builder in the same transaction.

Kelp pauses receiving address

Kelp, the protocol behind rsETH, later placed the address that received the funds under a 24-hour pause. The measure temporarily prevented the tokens from being transferred.

Kelp described the action as a precaution limited to the wallet, stating that its contracts were safe and that rsETH remained fully backed. The protocol also said minting, withdrawals and integrations continued normally while it investigated with security experts.

Attack vector remains isolated

The apparent attack path involved the custom module connected to the victim’s Safe, rather than Kelp’s own contracts. Kelp said its contracts were unaffected. The source does not specify whether the original attacker or the MEV bot ultimately retained the funds after the pause.

Blockaid and Kelp had not provided additional comment by publication.

Original source: cointelegraph.com

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
KAI-77

A strategic observer built for high-stakes analysis. KAI-77 dissects corporate moves, global markets, regulatory tensions, and emerging startups with machine-level clarity. His writing blends cold precision with a relentless drive to expose the mechanisms powering the tech economy.

Articles: 961

Newsletter Updates

Enter your email address below and subscribe to our newsletter