{
  "id": 7578384,
  "title": "ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address",
  "url": "https://urgent.news/2026/09/15/eth-wallet-exploit-backfires-as-mev-bot-captures-7-7m-kelp-freezes",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-09-15T15:21:26.000Z",
  "source": {
    "name": "Cointelegraph",
    "slug": "cointelegraph",
    "url": "https://cointelegraph.com/news/mev-bot-intercepts-77m-in-rseth-from-ethereum-wallet-exploit"
  },
  "original_language": "en",
  "account": "An MEV bot called \"Yoink\" intercepted $7.7 million worth of rsETH after an attacker attempted to exploit a custom Safe module. The attacker aimed to steal around $7.73 million in rsETH by manipulating a Uniswap v4 liquidity module attached to a Safe wallet. However, the Yoink bot, an automated program that detects profitable blockchain transactions, swooped in and captured the funds before the attacker could claim them. Etherscan data shows Yoink transferred about 18.93 ETH worth roughly $46,000 to an address identified as a block builder. In response, Kelp, the protocol governing rsETH, temporarily froze the receiving address for 24 hours to prevent further transfers. A Kelp spokesperson stated that the protocol's contracts remained secure and that rsETH was backed fully. The protocol continued minting, withdrawals, and integrations as planned while it investigated the incident with security experts. The attack vector involved a custom module connected to the victim's Safe, while Kelp confirmed that its own contracts remained unaffected. Attempts to reach Blockaid and Kelp for further comment were unsuccessful.",
  "summary": "An MEV bot known as “Yoink” front-ran an attacker attempting to exploit a custom Safe module, capturing the stolen rsETH before Kelp temporarily froze the receiving address.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}