Key Points
- A malicious actor attempted to drain $7.8 million worth of rsETH from a Safe wallet on Ethereum through a Uniswap v4 module vulnerability
- An automated MEV bot named “Yoink” successfully front-ran the exploit, securing the assets ahead of the hacker
- The bot paid approximately 19 ETH in fees to a block builder for transaction priority
- KelpDAO implemented a 24-hour freeze on the recipient address as a security measure
- Security firm BlockSec identified the issue stemmed from insufficient authorization validation in an executor contract associated with the Safe module
A sophisticated MEV bot operating under the name Yoink successfully prevented a $7.8 million rsETH theft on the Ethereum blockchain by front-running the malicious transaction before the hacker could execute it.
The attempted attack occurred on September 15, 2026, within Ethereum block 25980525. An unidentified threat actor sought to leverage a vulnerability in a custom module attached to a Safe smart contract wallet.
Blockchain security company Blockaid revealed that the attacker leveraged a public keeper multicall function to channel assets through a compromised Uniswap v4 hook pool. This mechanism enabled the conversion of aEthrsETH into rsETH, the liquid restaking token associated with KelpDAO.
However, the hacker’s plan failed. Yoink, an automated trading bot designed to identify and capitalize on profitable blockchain transactions, spotted the vulnerability and executed a competing transaction with higher priority.
The MEV Bot’s Strategy to Outpace the Hacker
Yoink successfully claimed 2,900 rsETH at the beginning of the block. The bot then transferred 2,882.37 rsETH to another wallet address while channeling the remaining 17.63 rsETH through the Uniswap v4 protocol.
Subsequently, the Pool Manager returned approximately 18.95 ETH to Yoink’s contract. The bot then forwarded 18.93 ETH to a block builder. This substantial payment functioned as the bot’s competitive bid to secure preferential positioning within the block.
The hacker’s original exploit transaction executed later within the identical block but failed. Security analysts confirm that the transaction sequence proves Yoink identified the threat and executed its counter-transaction first.
BlockSec’s investigation identified the vulnerability’s origin as inadequate authorization validation within an executor contract connected to the Safe wallet module. This weakness permitted external calls to bypass security through a pathway the wallet recognized as legitimate.
Importantly, this vulnerability did not affect Safe’s core smart contracts or Ethereum’s underlying infrastructure. The security gap was isolated to the executor contract associated with this specific wallet configuration.
KelpDAO’s Security Response
Following the incident, Kelp, the protocol responsible for rsETH, implemented a 24-hour pause on the address containing the intercepted funds. This temporary restriction prevented any token transfers from the affected address.
Kelp clarified that the pause only affected the specific wallet and that its protocol contracts remained secure. The platform’s minting functionality, withdrawal processes, and third-party integrations operated without interruption throughout the investigation period.
The development team confirmed that rsETH maintains complete collateralization and announced they were collaborating with security specialists to analyze the incident.
This marks rsETH’s second security challenge in 2026. Earlier in April, an attacker generated 116,500 unbacked rsETH tokens following a compromise of LayerZero’s verifier infrastructure, subsequently using these tokens as collateral on the Aave lending platform.
Security professionals have found no connection between these two events. Each exploit utilized distinct vulnerabilities and involved different wallet structures.
DeFi protocols have experienced significant losses throughout the year. According to CertiK and Forbes data referenced in a September analysis, decentralized finance platforms suffered over $1.3 billion in exploit-related losses during the first eight months of 2026.
Authorities have not announced any law enforcement proceedings related to Yoink or the attempted rsETH theft. The identities of the attacker, Yoink’s operator, and the block builder involved remain undisclosed.





