Ethereum Wallet Loses $7.8M in rsETH Exploit Foiled by MEV Bot
An Ethereum wallet lost approximately $7.8 million in an rsETH exploit on September 15, 2026. The attack was carried out using a custom Uniswap v4 liquidity pool Safe module linked to Kelp DAO's rsETH.
Blockaid, a blockchain security firm, investigated the incident and discovered that the attacker exploited a public entry point in the custom Safe module. This allowed the attacker to execute code inside the wallet's context and gain control over its assets.
The attacker first redirected the wallet's Uniswap v4 Safe module towards a malicious Hook pool using a public keeper multicall function. The module then unpacked the wallet's aEthrsETH into raw rsETH, which the attacker attempted to extract through the malicious pool.
However, the stolen funds were captured by an MEV bot called 'yoink' in Ethereum's mempool, leaving the original attacker empty-handed.