MEV bot Yoink intercepts $7.7M rsETH exploit, Kelp freezes address
In brief
- MEV bot Yoink intercepted $7.7M rsETH theft from compromised Safe wallet
- Attacker exploited custom Uniswap v4 liquidity module via public keeper multicall
- Kelp placed receiving address under 24-hour pause; protocol operations continue normally
How the exploit unfolded
An attacker exploited a custom module connected to an Ethereum Safe wallet in an attempt to extract roughly $7.7 million in rsETH. According to blockchain security firm Blockaid, the attacker used a public keeper multicall to direct a custom Uniswap v4 liquidity module into an attacker-created hooked pool — a technique designed to siphon funds from the victim's wallet.
But the Yoink bot moved faster. It intercepted the transaction and captured the rsETH before the exploit could complete. Etherscan data shows Yoink then transferred about 18.93 ETH, worth roughly $46,000, to an address labeled as a block builder in the same transaction.
Kelp's response
Kelp, the protocol behind rsETH, responded by placing the address that received the stolen funds under a 24-hour pause, temporarily preventing the tokens from being transferred. The move was strictly precautionary.
"This is a precautionary, wallet-level measure only," Kelp said. "Kelp contracts are safe, rsETH remains fully backed."
The protocol said minting, withdrawals and integrations were continuing normally while it worked with security experts to investigate the incident. Kelp emphasized that the attack vector involved the custom module connected to the victim's Safe, while its own contracts remained unaffected.
This distinction matters. The vulnerability wasn't in Kelp's core infrastructure — it was in how the victim had configured their Safe wallet with a third-party module. That setup created the opening an attacker tried to exploit, and that same opening is what allowed Yoink to step in.


