Urgent.News

What's breaking now, across thousands of outlets.

Finance & Markets

ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address

An MEV bot known as “Yoink” front-ran an attacker attempting to exploit a custom Safe module, capturing the stolen rsETH before Kelp temporarily froze the receiving address.

ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address

An MEV bot called "Yoink" intercepted $7.7 million worth of rsETH after an attacker attempted to exploit a custom Safe module. The attacker aimed to steal around $7.73 million in rsETH by manipulating a Uniswap v4 liquidity module attached to a Safe wallet. However, the Yoink bot, an automated program that detects profitable blockchain transactions, swooped in and captured the funds before the attacker could claim them.

Etherscan data shows Yoink transferred about 18.93 ETH worth roughly $46,000 to an address identified as a block builder. In response, Kelp, the protocol governing rsETH, temporarily froze the receiving address for 24 hours to prevent further transfers. A Kelp spokesperson stated that the protocol's contracts remained secure and that rsETH was backed fully.

The protocol continued minting, withdrawals, and integrations as planned while it investigated the incident with security experts. The attack vector involved a custom module connected to the victim's Safe, while Kelp confirmed that its own contracts remained unaffected. Attempts to reach Blockaid and Kelp for further comment were unsuccessful.

Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at cointelegraph.com →

More in Finance & Markets

More from Tuesday 15 September →