TLDR
- An attacker tried to steal $7.8 million in rsETH from an Ethereum Safe wallet using a custom Uniswap v4 module exploit
- MEV bot “Yoink” front-ran the attack, capturing the funds before the exploiter could
- Yoink paid nearly 19 ETH to a block builder to secure priority placement in the block
- Kelp, the protocol behind rsETH, froze the receiving address for 24 hours as a precaution
- BlockSec traced the vulnerability to weak authorization checks in an executor contract linked to a Safe module
An MEV bot called Yoink intercepted a $7.8 million attempted theft of rsETH on Ethereum, capturing the funds before the original attacker could claim them.
#PeckShieldAlert MEV bot yoink front-runs a ~$7.81M $rsETH exploit on Ethereum pic.twitter.com/vAJwsCOfsQ
— PeckShieldAlert (@PeckShieldAlert) September 15, 2026
The incident happened on September 15, 2026, in Ethereum block 25980525. An unknown attacker tried to exploit a custom module connected to a Safe smart contract wallet.
According to blockchain security firm Blockaid, the attacker used a public keeper multicall to route funds through a malicious Uniswap v4 hook pool. This allowed them to unwrap aEthrsETH into rsETH, the liquid restaking token tied to KelpDAO.
The attacker never got the funds. Yoink, an automated bot that scans blockchain transactions for profitable opportunities, detected the exploit and submitted a competing transaction first.
How the MEV Bot Beat the Attacker
Yoink received 2,900 rsETH at the top of the block. It sent 2,882.37 rsETH to a separate wallet address and routed the remaining 17.63 rsETH through Uniswap v4.
🚨 WILD: Ethereum MEV bot “Yoink” FRONT-RUNS a hacker’s $7.8 MILLION exploit and steals the entire loot.
A hacker attacked an Ethereum whale’s Gnosis Safe wallet using a custom Uniswap V4 hook to unwrap aETHrsETH into freely transferable rsETH.
But once the exploit hit the… pic.twitter.com/Pqi7eY7BJb
— Coin Bureau (@coinbureau) September 16, 2026
The Pool Manager then sent about 18.95 ETH back to the Yoink contract. Yoink forwarded 18.93 ETH of that to a block builder. This large payment was essentially the bot’s bid for priority placement in the block.
The original exploit transaction ran later in the same block and reverted. Security researchers say the ordering confirms Yoink detected the attack and moved first.
BlockSec traced the root cause to weak authorization checks in an executor contract linked to the Safe wallet module. The flaw allowed outside calls to pass through a route the wallet treated as trusted.
This was not a flaw in the core Safe contracts or Ethereum itself. The problem was specific to the executor contract tied to that particular wallet setup.
Kelp Responds With a Freeze
Kelp, the protocol behind rsETH, placed the address holding the funds under a 24-hour pause shortly after the incident. The pause blocked token transfers from that address.
Kelp said the measure was wallet-level only and that its own contracts remained safe. Minting, withdrawals, and integrations continued normally during the investigation.
The protocol confirmed rsETH remains fully backed and said it was working with security experts on the case.
This is not rsETH’s first security incident in 2026. In April, an attacker minted 116,500 unbacked rsETH after compromising LayerZero verifier infrastructure and used those tokens as collateral on Aave.
Security researchers have not linked the two incidents. They involved different weaknesses and separate wallet paths.
DeFi losses this year have been heavy. CertiK and Forbes estimates cited in a September report put protocol losses from exploits at over $1.3 billion in the first eight months of 2026.
No law enforcement action has been announced in connection with Yoink or the attempted rsETH exploit. The identity of the attacker, the Yoink operator, and the block builder remain unknown.







