An attacker's attempt to drain millions in staked Ether from an Ethereum wallet ended in an unusual twist this week, after a maximal extractable value bot swooped in to seize the funds before the hacker could claim them, and the affected protocol moved quickly to freeze the destination address.
How the Exploit Unfolded
The incident centered on a custom Safe module that a malicious actor sought to exploit in order to siphon rsETH — a liquid restaking token issued by Kelp — from a targeted Ethereum wallet. As the attacker moved to execute the theft, an MEV bot identified as "Yoink" detected the pending transaction and front-ran it.
By stepping ahead of the exploit in the transaction ordering, the bot intercepted roughly $7.7 million worth of rsETH that the attacker had intended to walk away with. The maneuver effectively turned the tables on the would-be thief, leaving the stolen assets in the hands of the automated trading bot rather than the original perpetrator.
The hacker set the trap, but a bot sprang it first — walking off with $7.7 million meant for the attacker.
Kelp Steps In
MEV bots operate by scanning the mempool for profitable opportunities and reordering, inserting, or front-running transactions to capture value. In most cases these bots are associated with practices that critics view as extractive, but here the mechanism inadvertently disrupted a theft in progress.
Following the interception, Kelp took action to freeze the receiving address holding the rsETH, temporarily locking down the assets and preventing any further movement of the tokens. The freeze reflects the ability of some token issuers to intervene when their assets are implicated in suspicious activity.
The episode highlights several dynamics at play in decentralized finance:
- Custom smart contract modules can introduce exploitable vulnerabilities.
- MEV bots can produce unpredictable outcomes, occasionally undercutting attackers.
- Token issuers retaining freeze capabilities can serve as a backstop during incidents.
The situation remains fluid as parties assess whether the intercepted funds can ultimately be recovered or returned. For now, the combination of an opportunistic bot and a swift protocol response prevented the exploit from paying off as its architect had planned.
