started · updated
MEV bot intercepts $7.8 million rsETH exploit on Ethereum
An attempted $7.8 million exploit of an Ethereum Safe wallet involving rsETH tokens was intercepted by an MEV bot named ‘Yoink’. The bot front-ran the attacker by paying nearly 19 ETH to secure priority placement in the Ethereum block, successfully capturing 2,900 rsETH before the original exploit transaction could complete.
Security researchers from Blockaid and PeckShield identified the vulnerability as stemming from weak authorization checks in an executor contract linked to a Safe module. The attacker reportedly used a public keeper multicall to route funds through a malicious Uniswap v4 hook pool designed to unwrap assets into rsETH.
In response to the incident, Kelp, the operator of the rsETH protocol, placed a 24-hour pause on the receiving address to investigate. Kelp stated that rsETH remains fully backed and that its core contracts were not impacted, noting that minting, withdrawals, and other integrations continued to function normally.
Entities
Blockaid · Ethereum · KelpDAO · PeckShield · Uniswap