BlocktoBlockto
MEV Bot Intercepts $7.7 Million Ethereum Wallet Exploit Before Attacker Could Cash Out
ETHEREUM NEWS

Photo: Illustrative

MEV Bot Intercepts $7.7 Million Ethereum Wallet Exploit Before Attacker Could Cash Out

An attacker attempting to drain roughly $7.7 million in rsETH from an Ethereum wallet was beaten to the funds by an automated trading bot, which captured the stolen tokens before the original exploiter could take control.

Tristan R.
By Tristan R.

Senior Author · September 15, 2026

2 min
Key takeaways
An attacker attempting to drain roughly $7.7 million in rsETH from an Ethereum wallet was beaten to the funds by an automated trading bot, which captured the stolen tokens before the original exploiter could take control.
How The Exploit Unfolded According to blockchain security , the attacker exploited a custom module connected to a Safe wallet, using a public multicall function to redirect a liquidity tool into a pool the attacker had created, allowing wrapped assets to be unwrapped into rsETH.
Before the attacker could claim the funds, an MEV bot known as Yoink, which scans blockchain activity for profitable opportunities, front-ran the transaction and captured the rsETH instead.

An attacker attempting to drain roughly $7.7 million in rsETH from an Ethereum wallet was beaten to the funds by an automated trading bot, which captured the stolen tokens before the original exploiter could take control.

How The Exploit Unfolded

According to blockchain security , the attacker exploited a custom module connected to a Safe wallet, using a public multicall function to redirect a liquidity tool into a pool the attacker had created, allowing wrapped assets to be unwrapped into rsETH. Before the attacker could claim the funds, an MEV bot known as Yoink, which scans blockchain activity for profitable opportunities, front-ran the transaction and captured the rsETH instead. Blockchain data shows the bot then sent a small portion, worth about $46,000, to an address associated with a block builder as part of the same transaction.

Kelp Pauses Address As Precaution

Kelp, the protocol behind rsETH, temporarily froze the wallet that received the intercepted funds for 24 hours as a precautionary step, stating that its core contracts remain secure and rsETH stays fully backed.

The protocol said minting, withdrawals and other integrations continued operating normally throughout the incident. The vulnerability was tied specifically to a custom module linked to the victim’s wallet rather than any flaw in Kelp’s own infrastructure, and the protocol said it is working with security researchers to investigate further.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.