Loading article…
An MEV bot named Yoink front-ran a $7.8 million rsETH exploit on Ethereum, capturing the funds before the attacker could secure them. See how it happened.
An automated MEV bot known as Yoink intercepted a $7.8 million exploit targeting a user’s rsETH holdings on the Ethereum network, effectively front-running the attacker to capture the assets [1]. The incident highlights the role of Maximal Extractable Value (MEV) bots, which monitor blockchain transactions for profitable opportunities, in the broader security landscape of decentralized finance [2].
| At a glance | |
|---|---|
| Assets Intercepted | $7.8 Million |
| Token Involved | rsETH |
| Protocol | KelpDAO |
| Incident Type | Wallet Exploit |
The exploit originated from a custom module connected to the victim’s Safe, a smart contract wallet, rather than a vulnerability within the Kelp protocol itself [1]. As the attacker attempted to move the rsETH, the Yoink bot identified the transaction and executed a front-running maneuver—a process where a bot pays higher gas fees to ensure its own transaction is processed before the target's [1]. By doing so, the bot captured the $7.8 million in rsETH before the original exploiter could take control of the funds [1].
Following the interception, Etherscan data revealed that the Yoink bot transferred approximately 18.93 ETH, valued at roughly $46,000, to an address identified as a block builder [1]. This payment is a common feature of MEV strategies, used to incentivize validators to prioritize the bot's transaction within a block [2].
Kelp, the protocol behind the rsETH token, responded by placing the address that received the intercepted funds under a 24-hour pause [1]. The protocol stated that this was a precautionary, wallet-level measure intended to prevent the movement of the tokens while the situation is assessed [1].
Kelp has maintained that its core contracts remain secure and that rsETH is fully backed [1]. According to the protocol, standard operations including minting, withdrawals, and integrations are continuing to function normally while the team works with security experts to investigate the specific attack vector [1].
The incident underscores the dual nature of MEV bots, which can act as both a source of market friction and, as seen here, a mechanism that can inadvertently disrupt malicious exploits. Whether the intercepted funds are returned to the original victim or remain with the bot operator remains an open question.
Coverage is mostly measured — 283 of 300 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Sep 16, 2026 · How we report
The Glamsterdam upgrade for Ethereum is targeted for activation on the Sepolia testnet on October 6, 2026, at 13:53 UTC. Mainnet activation for Ethereum is currently planned for the fourth quarter of 2026, though previous delays have created uncertainty regarding this timeline.
As of September 14, 2026, Ethereum is trading at $2,499.38. This price represents a 32.9% increase over the preceding 30-day period.
Ethereum base-layer transaction fees have fallen by 99% from 2021 levels primarily because layer-2 networks now process transactions separately before settling them on the main chain. While this shift has lowered costs for users, it has also reduced the volume of fees flowing directly to the Ethereum base layer.
Higher interest rates and tighter monetary policy, such as the potential quarter-point rate hike expected from the Federal Reserve on September 16, 2026, can pressure risk assets like Ethereum. Historically, Ethereum has shown higher sensitivity to these macroeconomic shocks compared to Bitcoin.