MEV Bot Steals $7.8 Million from Ethereum Hacker
On September 15, 2026, an automated trading bot named Yoink executed a high-stakes maneuver that left a hacker empty-handed. The bot intercepted $7.8 million in rsETH, Kelp DAO’s liquid restaking token, just as an attacker attempted to siphon the funds from a misconfigured Safe wallet. Yoink paid approximately 18.93 ETH, or $46,000, to an Ethereum block builder to ensure its transaction was processed first, effectively stealing the stolen funds.
The incident highlights the growing power of MEV (Maximal Extractable Value) bots, which monitor Ethereum’s mempool for profitable opportunities. Yoink identified the attacker’s transaction, replicated its logic, and submitted a competing bundle with a higher payment to the block builder. The builder prioritized Yoink’s transaction, leaving the original attacker with nothing. Whether Kelp DAO or its users will recover the funds remains uncertain.
This event underscores the evolution of MEV, where bots no longer just reorder trades for profit but actively race attackers to exploit vulnerabilities. The bot’s actions raise ethical questions, as operators behind such bots are often anonymous, and intercepted funds are not always returned to victims. Kelp DAO’s rsETH has already been involved in another major exploit earlier in 2026, highlighting ongoing security challenges in DeFi.
MEV bots, or searchers, use private order flow to submit transactions directly to block builders through encrypted relays. This infrastructure, originally designed to reduce gas waste, now decides who profits from hacks. Estimates suggest Ethereum’s annual MEV extraction has grown significantly, reaching close to $2.5 billion in 2026, driven by arbitrage, liquidations, and exploit front-running.