MEV Bot 'Yoink' Intercepts $7.7M in Failed ETH Wallet Attack, Kelp Implements Address Freeze

MEV Bot 'Yoink' Intercepts $7.7M in Failed ETH Wallet Attack, Kelp Implements Address Freeze

A custom Safe module exploitation attempt was derailed when the MEV bot 'Yoink' intercepted the attacker's transaction, securing the rsETH tokens before Kelp implemented a temporary freeze on the destination address.

A malicious actor leveraged a custom module linked to an Ethereum Safe wallet to drain approximately $7.7 million worth of rsETH, but the scheme was foiled when an MEV bot seized the assets mid-transaction.

Blockchain security company Blockaid reported that the malicious actor utilized a public keeper multicall function to manipulate a custom Uniswap v4 liquidity module, redirecting it through an attacker-controlled hooked pool where aEthrsETH tokens were converted to rsETH.

The compromised wallet was identified by Blockaid as a Safe owned by an anonymous user, with the security firm noting that approximately $7.73 million in rsETH had been compromised at the moment of their first disclosure.

Blockaid report screenshot
Source: Blockaid

However, the exploitation was intercepted by an MEV bot called Yoink, a sophisticated automated system designed to scan blockchain transactions and identify lucrative arbitrage opportunities. This bot successfully secured the rsETH tokens before the initial attacker could gain possession of the assets, with Etherscan records indicating that Yoink sent approximately 18.93 ETH, valued at around $46,000, to an address designated as a block builder within the same transaction.

Following this incident, Kelp, the organization responsible for the rsETH protocol, imposed a 24-hour pause on the address that had received the intercepted funds, effectively freezing any transfers of the tokens on a temporary basis. "This is a precautionary, wallet-level measure only," Kelp said. "Kelp contracts are safe, rsETH remains fully backed."

KelpDAO statement
Source: KelpDAO

According to the protocol's statement, minting operations, withdrawal functions and protocol integrations remained operational without interruption as the team collaborated with security professionals to examine the incident thoroughly. The vulnerability appeared to stem from the custom module attached to the victim's Safe wallet, with Kelp emphasizing that their core contracts remained secure and uncompromised.

Cointelegraph contacted Blockaid and Kelp for additional comment but had not received a response by publication.

← Torna al blog