ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address
An MEV bot known as “Yoink” front-ran an attacker attempting to exploit a custom Safe module, capturing the stolen rsETH before Kelp temporarily froze the receiving address.

An MEV bot known as “Yoink” front-ran an attacker attempting to exploit a custom Safe module, capturing the stolen rsETH before Kelp temporarily froze the receiving address.
An attacker exploited a custom module connected to an Ethereum Safe wallet in an attempt to extract roughly $7.7 million in rsETH, only to have the funds intercepted by an MEV bot.
According to blockchain security firm Blockaid, the attacker used a public keeper multicall to direct a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where aEthrsETH was unwrapped into rsETH.
The attack was then front-run by an MEV bot known as Yoink, an automated program that monitors blockchain transactions for profitable opportunities. The bot captured the rsETH before the original exploiter could take control of the funds, while Etherscan data shows Yoink transferred about 18.93 ETH, worth roughly $46,000, to an address labeled as a block builder in the same transaction.