An attempt to drain roughly $7.7 million in rsETH from an Ethereum Safe wallet failed to pay off for the attacker, because an MEV bot reached the funds first, according to Cointelegraph.
The incident, reported on September 15, 2026, began with the exploitation of a custom module linked to the Safe wallet. Blockchain security firm Blockaid said the attacker used a public keeper multicall to route a custom Uniswap v4 liquidity module into a hooked pool the attacker had created, where aEthrsETH was unwrapped into rsETH. Blockaid identified the wallet as one belonging to an unidentified user and put the loss at about $7.73 million at the time of its initial report.
Also read: US Senate Fails Cloture Vote on CLARITY Act as Bitcoin Slides Below $76K
Before the exploiter could take control of the tokens, an automated MEV bot named Yoink front-ran the transaction. Etherscan data cited in the report shows Yoink sending roughly 18.93 ETH, valued at about $46,000, to an address labeled as a block builder within the same transaction.
Key facts
- An attacker targeted a custom Uniswap v4 liquidity module connected to a Safe wallet holding rsETH.
- Blockaid estimated about $7.73 million in rsETH was lost at the time of its initial report.
- The MEV bot Yoink front-ran the attacker and captured the rsETH first.
- Yoink transferred about 18.93 ETH, worth roughly $46,000, to an address labeled as a block builder in the same transaction.
- Kelp placed the receiving address under a 24-hour pause as a precautionary, wallet-level measure.
Kelp pauses address and defends its contracts
Kelp, the protocol behind rsETH, said the pause applied only to the address that received the funds, temporarily preventing the tokens from being moved. In its statement, Kelp called the step precautionary and described it as a wallet-level measure, adding that its contracts are safe and that rsETH remains fully backed.
Also read: UK FCA Gets 123 Tokenization Responses, Plans Joint Roadmap With Bank of England
The protocol said minting, withdrawals and integrations were continuing as normal while it worked with security experts on the investigation. According to the report, the apparent route of attack was the custom module attached to the victim’s Safe, not Kelp’s own contracts.
Cointelegraph said it contacted Blockaid and Kelp for additional comment but had not received a response by publication.
Why it matters
Safe wallets are widely used by individuals and teams to hold large token positions, and custom modules extend those wallets with extra functionality. When a module carries a flaw, the exposure sits with the wallet owner rather than with the issuing protocol, which is the distinction Kelp drew in its public statement. The episode also illustrates how competitive the MEV market has become: a bot can strip the profit from a live exploit before the exploiter converts stolen tokens, leaving the victim’s position frozen rather than freely traded. For rsETH holders, the protocol’s position is that backing and operations are unchanged, but the funds tied to this specific address remain locked for the duration of the pause.
What to watch
The 24-hour pause on the receiving address is the nearest point to watch, along with any further findings from Kelp’s investigation with security experts and any comment from Blockaid or Kelp in response to Cointelegraph’s request. Whether the attacker’s custom module is used again on other Safe wallets is also an open question.
Reported by cointelegraph.com.

Be the first to comment