A security incident involving an Ethereum Safe wallet resulted in an attempted theft of approximately $7.73 million in rsETH, which was intercepted by an automated MEV bot known as Yoink. According to blockchain security firm Blockaid, the attacker exploited a custom Uniswap v4 liquidity module connected to the victim's Safe, directing it into a hooked pool to unwrap aEthrsETH into rsETH. Before the original exploiter could secure the funds, Yoink captured the rsETH and transferred about 18.93 ETH, valued at roughly $46,000, to a block builder address within the same transaction.
Following the interception, Kelp, the protocol behind rsETH, placed the address that received the funds under a 24-hour pause to prevent token transfers. Kelp described this action as a precautionary, wallet-level measure, stating that its contracts remained safe and rsETH fully backed. The protocol confirmed that minting, withdrawals, and integrations continued normally while it collaborated with security experts to investigate the incident. Blockaid identified the affected wallet as belonging to an unidentified user, noting that the attack vector involved the custom module rather than Kelp’s core infrastructure.
This incident highlights the complex interplay between decentralized finance vulnerabilities and the competitive dynamics of maximal extractable value (MEV). While the initial exploit targeted a specific configuration error in a custom Uniswap v4 module attached to a Safe wallet, the intervention by the Yoink bot demonstrates how automated systems can inadvertently act as a layer of protection—or competition—against malicious actors. The fact that the funds were captured before the attacker could consolidate control suggests that high-value transactions are increasingly subject to real-time scrutiny by sophisticated bots, altering the risk profile for both attackers and legitimate users who rely on standard wallet infrastructures.
From a market structure perspective, Kelp’s decision to freeze the receiving address underscores the tension between decentralization principles and centralized emergency response capabilities. Although Kelp asserted that its contracts were unaffected and the measure was merely precautionary, the ability to pause token transfers at the wallet level indicates that certain DeFi protocols retain significant administrative controls over asset movement. This operational capability may reassure institutional investors regarding immediate containment of losses, yet it also raises questions about censorship resistance and the extent to which protocol teams can intervene in on-chain activity without compromising the trustless nature of the underlying technology.


