An MEV bot intercepted approximately $7.7 million in rsETH from an attacker attempting to exploit an Ethereum Safe wallet. The bot, known as Yoink, captured the funds before the attacker could, and Kelp subsequently froze the receiving address as a precautionary measure.
This incident highlights the complex interplay between DeFi exploits, MEV bots, and protocol security measures, demonstrating how automated bots can intercept stolen funds and alter the outcome of attempted attacks, while also showcasing the immediate response mechanisms available to protocols like Kelp to mitigate further losses.
An attempt to steal approximately $7.73 million in rsETH from an Ethereum Safe wallet was thwarted when an MEV bot front-ran the attacker. The bot, known as Yoink, intercepted the funds before the exploiter could gain control. According to blockchain security firm Blockaid, the attacker used a custom Uniswap v4 liquidity module to unwrap aEthrsETH into rsETH. Yoink then transferred about 18.93 ETH, valued at approximately $46,000, to an address identified as a block builder. In response, Kelp, the protocol behind rsETH, placed the receiving address under a 24-hour pause as a precautionary measure, emphasizing that its own contracts remain secure and rsETH is fully backed. Minting, withdrawals, and integrations are continuing normally while security experts investigate the incident. The apparent attack vector involved the custom module connected to the victim's Safe wallet.