A security incident involving an Ethereum Safe wallet resulted in an attempted theft of approximately $7.73 million in rsETH, which was intercepted by an automated MEV bot known as Yoink. According to blockchain security firm Blockaid, the attacker exploited a custom Uniswap v4 liquidity module connected to the victim's Safe, directing it into a hooked pool to unwrap aEthrsETH into rsETH. Before the original exploiter could secure the funds, Yoink captured the rsETH and transferred about 18.93 ETH, valued at roughly $46,000, to a block builder address within the same transaction.

Following the interception, Kelp, the protocol behind rsETH, placed the address that received the funds under a 24-hour pause to prevent token transfers. Kelp described this action as a precautionary, wallet-level measure, stating that its contracts remained safe and rsETH fully backed. The protocol confirmed that minting, withdrawals, and integrations continued normally while it collaborated with security experts to investigate the incident. Blockaid identified the affected wallet as belonging to an unidentified user, noting that the attack vector involved the custom module rather than Kelp’s core infrastructure.