MEV Bot Foils $7.7M Ethereum Wallet Exploit, Captures Funds
An attempt to exploit an Ethereum Safe wallet resulted in $7.7 million being intercepted by an MEV bot, known as Yoink.
According to Blockaid, a blockchain security firm, the attacker used a public keeper multicall to redirect a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where ETH was unwrapped into rsETH. The affected wallet belonged to an unidentified user and about $7.73 million in rsETH had been lost at the time of Blockaid's initial report.
The attack was front-run by Yoink, which captured the rsETH before the original exploiter could take control of the funds. Etherscan data shows that Yoink transferred around 18.93 ETH, worth approximately $46,000, to an address labeled as a block builder in the same transaction.
Kelp, the protocol behind rsETH, subsequently placed the address receiving the funds under a 24-hour pause, temporarily preventing the tokens from being transferred. Kelp stated that this was a precautionary measure and emphasized that its contracts were safe, with rsETH remaining fully backed. Minting, withdrawals, and integrations continued normally while the incident was being investigated.