
An automated MEV bot front-ran an attacker's attempt to steal millions in rsETH, prompting a temporary pause by KelpDAO.
AI-generated summary
An attacker targeted an Ethereum Safe wallet via a custom module, attempting to extract rsETH before an MEV bot intervened.
An attacker exploited a custom module connected to an Ethereum Safe wallet in an attempt to extract roughly $7.7 million in rsETH, only to have the funds intercepted by an MEV bot.
According to blockchain security firm Blockaid, the attacker used a public keeper multicall to direct a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where aEthrsETH was unwrapped into rsETH.
Blockaid identified the affected wallet as a Safe belonging to an unidentified user and said about $7.73 million in rsETH had been lost at the time of its initial report.
The attack was then front-run by an MEV bot known as Yoink, an automated program that monitors blockchain transactions for profitable opportunities. The bot captured the rsETH before the original exploiter could take control of the funds, while Etherscan data shows Yoink transferred about 18.93 ETH, worth roughly $46,000, to an address labeled as a block builder in the same transaction.
Kelp, the protocol behind rsETH, subsequently placed the address that received the funds under a 24-hour pause, temporarily preventing the tokens from being transferred. “This is a precautionary, wallet-level measure only,” Kelp said. “Kelp contracts are safe, rsETH remains fully backed.”
The protocol said minting, withdrawals and integrations were continuing normally while it worked with security experts to investigate the incident. The apparent attack vector involved the custom module connected to the victim’s Safe, while Kelp said its own contracts were unaffected.
Cointelegraph contacted Blockaid and Kelp for additional comment but had not received a response by publication.
AI outlook — possibilities, not facts
KelpDAO or security experts will provide updates on the investigation after the 24-hour pause expires.
Likely · Within days

Recent data indicates mobile bandwidth for Bitcoin's Silent Payments is manageable at about 8 MB per day, but light wallets face severe risks of undiscovered payments if indexers omit data.

Atlantic Council experts warn that voluntary AI development slowdown commitments may fail under commercial pressure and U.S.-China rivalry without enforceable, independent safety standards.

Ethereum and Coinbase-backed Base network have abandoned efforts to agree on a shared account-abstraction standard, with Ethereum advancing EIP-8141 Frame Transactions and Base pursuing EIP-8130 separately, potentially forcing wallets to support different transaction architectures across networks.

Lido contributors debated Ethereum's enshrined proposer-builder separation (ePBS) design, focusing on payment guarantees for builders, costs of idle ETH and failed delivery, and the role of trusted connections versus open bidding. Discussions included Glamsterdam's testnet progress, relay dependencies, and operator configuration impacts on validator access to block-building opportunities.

Circle has named BlackRock, DTCC, Visa, Mastercard, and ICE as founding validators for its Arc blockchain mainnet launching Sept. 16, with over 100 institutions building on the private network. The permissioned validator model gives institutions a role in transaction finality while separating liability for third-party applications, and Circle plans future integration of tokenized assets and a potential shift to Proof-of-Stake by 2028.

OpenAI CEO Sam Altman called on AI companies to slow development to strengthen safety measures and prevent loss of human control or concentration of power, urging proactive safeguards without waiting for legislation.