A MEV exploit attempt on the Ethereum network led to an unexpected outcome after the attacking MEV bot had already been involved and seized the funds before it could take control. According to cybersecurity firm Blockaid, the attacker targeted a dedicated module associated with a Safe wallet in an attempt to extract approximately $7.7 million in rsETH.

According to technical details, the attacker used a public keeper multicall to route a dedicated liquidity unit of the Uniswap v4 type to a hooked pool created by himself, where the binding of aEthrsETH was undone and converted into rsETH. Blockaid said the affected wallet belonged to an unknown user, and the value reportedly lost at the time of the initial report was about $7.73 million in rsETH.

But the operation did not go as the attacker planned. A known MEV bot called Yoink stepped in: an automated program that monitors blockchain transactions for profitable opportunities, enabling it to front-run the operation and take rsETH before the attacker could get their hands on the funds. Etherscan data shows that Yoink also transferred about 18.93 ETH—worth roughly $46,000—to an address labeled as the block builder within the same transaction.

Later, Kelp—the entity associated with the rsETH protocol—took a precautionary step by placing the address that received the funds under pause for 24 hours, temporarily preventing the tokens from being transferred. The company confirmed that this action applies only at the wallet level, that Kelp’s own contracts are safe, and that rsETH is still fully supported.

As Kelp explained, minting, withdrawals, and integrations continued normally, while it worked with security experts to investigate the incident. Based on the available details, it appeared that the attack path targeted the module dedicated to the victim’s Safe wallet, whereas Kelp’s own contracts were not affected.

This incident highlights two important points: first, on-chain exploitation attempts can backfire when automated MEV systems catch them in time; second, temporary freezing mechanisms or address-level control can be a crucial tool to limit asset movement when a potential theft is suspected. The event also underscores the importance of thorough security audits for custom Safe modules, especially when used with complex execution paths or routable liquidity aggregators.

#أمن_البلوكشين #إيثريوم $ETH $RSETH