An attempted exploit of an Ethereum wallet backfired in spectacular fashion this week when an MEV bot front-ran the attacker and made off with roughly 7.7 million USD in rsETH before the thief could secure the funds. The unusual sequence, confirmed by blockchain security firm Blockaid, highlights the strange mechanics of Ethereum’s transaction ordering market, where automated arbitrage programs constantly watch the mempool for profitable opportunities, sometimes including those created by criminals.
How the attack unfolded
According to Blockaid, the attacker targeted a Safe wallet belonging to an unidentified user. Rather than exploiting the Safe’s core contracts, the attacker abused a custom module connected to the wallet. Using a public keeper multicall, the attacker directed a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where aEthrsETH, the staked version of rsETH supplied as collateral on Aave, was unwrapped into plain rsETH.
At the time of Blockaid’s initial report, approximately 7.73 million USD worth of rsETH had been drained from the wallet through the malicious module. The attack vector is a reminder that smart contract wallets are only as secure as their least-audited extension: modules attached to a Safe inherit sweeping permissions over its funds, and a single compromised module can empty the entire vault even when the Safe itself is sound.
Enter Yoink, the MEV bot
What should have been a routine theft instead turned into a race. An MEV bot known as Yoink, an automated program that monitors pending blockchain transactions for profitable backrunning and sandwich opportunities, detected the exploit transaction in flight and captured the rsETH before the original exploiter could take control of the funds.
MEV, short for maximal extractable value, refers to the profit that can be extracted from reordering, inserting or censoring transactions within a block. Bots compete fiercely for these opportunities, paying substantial bribes to block builders for priority placement. Etherscan data shows Yoink transferred about 18.93 ETH, worth roughly 46,000 USD, to an address labeled as a block builder in the same transaction, a fee that secured the bot’s winning position in the block.
The result is a curious twist on crypto crime: the funds were stolen twice over, first from the victim by the exploiter’s module, and then from the exploiter by a bot that simply moved faster. Cases like this have precedent in the MEV world, where exploit front-running has occasionally returned funds to victims, though there is no guarantee of recovery when a bot gets there first.
Kelp freezes the address
Kelp, the restaking protocol behind rsETH, responded quickly. The protocol placed the address that received the funds under a 24-hour pause, temporarily preventing the rsETH from being transferred onward. In a statement, Kelp stressed that the move was narrow in scope.
“This is a precautionary, wallet-level measure only,” the protocol said. “Kelp contracts are safe, rsETH remains fully backed.”
Kelp added that minting, withdrawals and integrations were continuing normally while it worked with security experts to investigate the incident. The protocol’s own contracts were unaffected by the attack, which hinged entirely on the custom module attached to the victim’s Safe wallet. Cointelegraph contacted both Blockaid and Kelp for additional comment but had not received a response by publication.
Custom modules in the spotlight
The incident puts a fresh spotlight on the risk profile of modular smart contract wallets. Safes are widely regarded as among the most battle-tested multisig infrastructure in the industry, but their extensibility, the ability to bolt on custom modules for automation, gas abstraction and liquidity management, widens the attack surface considerably. A hooked Uniswap v4 pool, in this case, served as the drain mechanism, unwrapped collateral and routed it to the attacker in a single keeper-triggered call.
Security researchers have repeatedly warned that module permissions tend to accumulate silently, and that users frequently forget which third-party integrations retain sweeping rights over their wallets. For restaking protocols, the episode is also a stress test of incident response: Kelp’s wallet-level freeze stopped short of pausing the protocol, an approach that protected rsETH holders while leaving the underlying system fully operational.
For now, the 7.73 million USD in rsETH sits frozen at an address neither the exploiter nor the bot can freely move, while the victim, Kelp and security teams work through the aftermath. The episode is a vivid illustration that on Ethereum, the line between thief, rescuer and opportunist can come down to milliseconds and a builder bribe.
Market snapshot at publication: Bitcoin trades near 75,825 USD, Ethereum near 2,404 USD, and Solana near 98 USD, according to CoinGecko data.
An MEV bot named Yoink paying 18.93 ETH in builder bribes to backrun an exploiter and grab 7.7M in rsETH before he could. Most cyberpunk story of the week.
losing 7.7 million to a bot named Yoink is a level of humiliation nobody budgets for
imagine watching yoink take the bag on the exact tx you designed. therapy money fr
18.93 ETH to a builder for a backrun that nets 7.7M is like a 0.1 percent tip. crazy that the most honest actor in this whole story is the bot
an MEV bot frontrunning a wallet drainer out of 7.7M rsETH is the most cyberpunk thing ive read all week. the thief got yoinked on his own exploit
^ the bot just did bots things tbh. watched the mempool, saw free money, took it. zero morals, perfect execution
Everyone is laughing at the exploiter but the real story is the custom Safe module. Nobody audits those modules and this is exactly how wallets get drained while the Safe contracts stay untouched.
hard agree on modules, but lets be real, nobody is auditing a keeper multicall either. the attacker routed a legit v4 liquidity module into his own hooked pool. no signature, no drama, just plumbing
Dmitri is right about modules, but the aEthrsETH unwrap through a hooked Uniswap v4 pool is the scary part. attacker-controlled hooks were always gonna be the weak link
Kelp freezing the receiving address for 24 hours was quick thinking, but the whole rescue only worked because a bot was faster than both the exploiter and the Safe owner. Feels improvised.
18.93 ETH to win 7.7M is the most efficient trade of the year. meanwhile i overpay 40 gwei on a memecoin buy
Kelp freezing the receiving address saved the owner here, but that only works because the funds were rsETH. plain ETH would be gone in one block. Feels like luck dressed up as security.
the 24h freeze is a script kelp runs for exactly this case, not luck. but yeah plain eth and the bot just keeps it, nobody refunds you