An attacker thought they had found an easy $7.7 million payday inside a Kelp DAO-linked wallet. Instead, they got beaten to the punch by a piece of automated code with a mischievous name: Yoink. The MEV bot rsETH exploit that unfolded this month is one of those rare blockchain stories where the villain of the plot ends up losing to an even faster opportunist, and the funds in question land somewhere nobody planned for.
Key takeaways
- An attacker exploited a custom Uniswap v4 liquidity module tied to a Safe wallet, attempting to drain roughly $7.7 million in rsETH.
- An MEV bot known as Yoink front-ran the malicious transaction and intercepted the funds before the attacker could take control of them.
- Kelp, the protocol behind rsETH, placed the address that received the intercepted funds under a 24-hour precautionary pause.
- Kelp said its own smart contracts were unaffected, that rsETH remained fully backed, and that minting, withdrawals and integrations continued normally.
- In the same transaction, Yoink also transferred roughly 18.93 $ETH, valued at about $46,000, to an address identified as a block builder, based on Etherscan data cited by Cointelegraph.
MEV Bot Yoink Front-Runs $7.7M rsETH Exploit on Kelp DAO
The incident, first flagged by blockchain security firm Blockaid and reported by Cointelegraph, centered on a Safe wallet connected to a custom module built on Uniswap v4. According to Blockaid, the attacker used a public keeper multicall to steer that module into an attacker-created hooked pool, where aEthrsETH tokens were unwrapped into rsETH. That maneuver was designed to strip roughly $7.73 million worth of rsETH out of the wallet.
It almost worked. But the transaction never made it to the finish line the attacker had in mind.
Mechanism of Front-Running via Mempool Visibility
Public blockchains expose pending transactions before they are confirmed, which means anyone watching the mempool can see an exploit coming and try to beat it to execution. That transparency is exactly what let Yoink react in time. The bot, described by Bitcoinist as an MEV searcher scanning for profitable opportunities, spotted the exploit attempt in the mempool and submitted its own transaction capable of executing first.
This is the double-edged nature of maximal extractable value activity on Ethereum: the same visibility that lets bad actors plan an attack also lets other bots spot it and jump the queue.
Yoink Bot’s Interception of Stolen Assets
Yoink’s transaction beat the attacker to the vulnerable rsETH, capturing the funds before the original exploiter could gain control of them. Etherscan data cited by Cointelegraph shows that in the same transaction, Yoink also transferred about 18.93 $ETH — worth roughly $46,000 at the time — to an address labeled as a block builder, a detail that hints at how the bot compensated whoever helped get its transaction included first.
Kelp DAO’s Protocol Response and Asset Freezing
Kelp‘s response was fast and narrowly targeted: rather than shutting down the whole protocol, it froze the specific address that had received the intercepted rsETH. That single move mattered because it prevented the tokens from being moved again while the team figured out what had actually happened.
Protocol Pausing to Secure Intercepted Funds
Kelp placed the receiving address under a 24-hour pause, temporarily blocking any transfer of the tokens sitting there. In a public statement, Kelp described the move plainly: “This is a precautionary, wallet-level measure only,” the protocol said, adding that “Kelp contracts are safe, rsETH remains fully backed.” The team also said minting, withdrawals and integrations were continuing normally throughout, and that it was working with security experts to investigate the incident further.
Distinction Between Asset Interception and Recovery
Catching the funds before the attacker did is not the same thing as putting them safely back where they belong. Bitcoinist’s reporting on the episode underlined that gap directly: intercepting assets and completing a recovery are two very different stages, and the funds still had to be secured while the protocol worked out its next steps. A frozen address buys time. It does not, by itself, close the case.
Security Implications of the Exploit on Kelp Protocol
Even a defensive win carries a warning label. The fact that an outside bot had to step in to stop a $7.7 million loss shows that the vulnerability sitting in the custom module was real and exploitable, even though Kelp maintained that its core smart contracts were never compromised. The attack vector, according to Cointelegraph’s reporting, ran through the custom Uniswap v4 liquidity module connected to the victim’s Safe wallet, not through Kelp’s own contract code.
Revealed Vulnerabilities and Emergency Measures
That distinction matters for anyone trying to gauge how serious this was. Kelp’s contracts staying intact is reassuring, but the episode still forced an emergency wallet-level pause and an active investigation involving outside security specialists — not the kind of response a protocol mounts over a non-event. This is where the story becomes a genuine case study: a near-miss that still exposed a real weak point in the surrounding infrastructure, even if the core protocol logic held up.
Dual Nature of MEV Activity in Blockchain Ecosystem
What makes this episode worth watching beyond Kelp itself is the reminder it offers about how MEV bots behave on public chains. The same mempool transparency that lets attackers plan a theft also lets bots like Yoink spot the opportunity and race to intercept it first. That is not a fail-safe built into DeFi by design — it is closer to a lucky byproduct of competitive, profit-seeking automation. In practice, it means protocols can sometimes get an unplanned assist from the very actors typically cast as risks, even though nothing about that outcome was guaranteed.
FAQ
What did the MEV bot Yoink do during the Kelp rsETH exploit?
Yoink front-ran the exploit transaction and intercepted approximately $7.7 million worth of rsETH before the attacker could steal it.
Did Kelp DAO lose the $7.7 million during the exploit?
No, the intercepted assets were frozen after Kelp paused parts of its protocol, preventing the attacker from stealing the funds, although interception does not guarantee recovery.
Why did Kelp pause parts of its protocol during the incident?
Kelp paused smart contract operations to assess the situation and secure the intercepted assets after the exploit was front-run by the MEV bot.
What security concerns did this incident reveal about Kelp’s protocol?
The exploit exposed a significant vulnerability in the Kelp protocol that required emergency actions like pausing the protocol to prevent losses.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
crypto.news
cryptopolitan.com
cryptoslate.com