An attacker sought to exploit a custom module linked to an Ethereum Safe wallet to steal approximately $7.7 million in rsETH. However, an automated MEV bot intervened and seized the majority of the funds before the original exploit could be completed.
Attack on Safe wallet and intervention
Blockchain security firm Blockaid reported that the exploit began when the attacker utilized a public keeper multicall to route a custom Uniswap v4 liquidity module into a specially crafted pool, known as a “hooked pool.” Through this process, aEthrsETH was unwrapped and converted into rsETH, an Ethereum-based synthetic token.
The targeted wallet was identified as a Safe tied to an unidentified user. Blockaid stated the loss amounted to around $7.73 million in rsETH at the time of discovery.
As the attacker attempted to extract the rsETH, a well-known MEV bot called Yoink monitored and intercepted the transaction. MEV (Maximal Extractable Value) bots routinely scan blockchain activity to capitalize on valuable opportunities ahead of other participants by front-running transactions.
Blockchain data revealed that Yoink succeeded in acquiring the rsETH before the exploiter and, during the same transaction, transferred 18.93 ETH—about $46,000—into an address recognized as a block builder.
Mini dictionary: MEV bot – An automated program that detects lucrative blockchain transactions in real time and acts to maximize profit, particularly by prioritizing or front-running pending transactions.
Kelp’s response and ongoing investigation
Kelp, an Ethereum protocol responsible for issuing rsETH, responded to the incident by imposing a 24-hour transfer pause on the wallet that received the compromised tokens. This action was described as a temporary, wallet-level safeguard to prevent further movement of the tokens.
Kelp stated that the protocol’s contracts remain secure and that “rsETH remains fully backed.”
Despite the pause on the implicated wallet, Kelp confirmed that minting, withdrawals and other integrations continued as usual. The protocol said it is working with security experts to examine the details of the exploit. According to Kelp, only the custom module attached to the victim’s Safe was exploited, with the core Kelp contracts unaffected.
Ongoing monitoring and next steps
Blockaid and Kelp were approached for further comment, but neither had provided additional statements by the time of publication.
The investigation is ongoing as the teams work to determine the full impact and ensure the continued security of user funds within the protocol.




