ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address

Summary

An attacker targeted a Safe wallet connected to a custom Uniswap v4 liquidity module and tried to drain about $7.7 million in rsETH. Blockaid said the attacker used a public keeper multicall to route funds through an attacker-created hooked pool, where aEthrsETH was unwrapped into rsETH. Before the attacker could control the stolen assets, an MEV bot called Yoink front-ran the transaction and intercepted the rsETH. On-chain data also shows Yoink sent about 18.93 ETH to a block-builder address in the same transaction. Kelp, the protocol behind rsETH, then placed the receiving address under a 24-hour pause to stop further transfers. Kelp said this was only a wallet-level precaution, that its contracts were not compromised, and that rsETH remained fully backed. Minting, withdrawals, and integrations continued operating normally while the incident was investigated.