Ethereum Wallet Exploit Nets $7.7M, But an MEV Bot Beats the Attacker to It
An attacker attempted to exploit a custom module connected to an Ethereum Safe wallet, aiming to extract around $7.7 million worth of rsETH tokens. According to blockchain security firm Blockaid, the attacker used a public keeper multicall to manipulate a custom Uniswap v4 liquidity module, routing it into an attacker-created pool where wrapped tokens were converted into rsETH.
Before the attacker could claim the stolen funds, an automated trading program known as an MEV bot, nicknamed Yoink, detected the opportunity and front-ran the transaction, capturing the rsETH for itself. The bot then transferred a portion of the proceeds to an address linked to a blockchain 'block builder'.
Kelp, the protocol behind rsETH, responded by placing a 24-hour precautionary pause on the wallet that received the funds, stating this was a wallet-level measure only and that its core contracts remained secure and fully backed. The protocol confirmed that minting, withdrawals and other integrations continued operating normally while it worked with security researchers to investigate further. The incident appears to stem from a vulnerability in a custom module attached to the victim's wallet rather than any flaw in Kelp's own infrastructure.