# MEV Bot Yoink Intercepts $7.8M rsETH Exploit on Ethereum

**Published:** 2026-09-16T13:14:13.043Z  
**Topic:** Ethereum  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/44e2c47d-d415-4263-a46c-73981a390768

An MEV bot named Yoink front-ran a $7.8 million rsETH exploit on Ethereum, capturing the funds before the attacker could secure them. See how it happened.

An automated MEV bot known as Yoink intercepted a $7.8 million exploit targeting a user’s rsETH holdings on the Ethereum network, effectively front-running the attacker to capture the assets [1]. The incident highlights the role of Maximal Extractable Value (MEV) bots, which monitor blockchain transactions for profitable opportunities, in the broader security landscape of decentralized finance [2].

| At a glance | |
|---|---|
| Assets Intercepted | $7.8 Million |
| Token Involved | rsETH |
| Protocol | KelpDAO |
| Incident Type | Wallet Exploit |

## The mechanics of the interception
The exploit originated from a custom module connected to the victim’s Safe, a smart contract wallet, rather than a vulnerability within the Kelp protocol itself [1]. As the attacker attempted to move the rsETH, the Yoink bot identified the transaction and executed a front-running maneuver—a process where a bot pays higher gas fees to ensure its own transaction is processed before the target's [1]. By doing so, the bot captured the $7.8 million in rsETH before the original exploiter could take control of the funds [1].

Following the interception, Etherscan data revealed that the Yoink bot transferred approximately 18.93 ETH, valued at roughly $46,000, to an address identified as a block builder [1]. This payment is a common feature of MEV strategies, used to incentivize validators to prioritize the bot's transaction within a block [2].

## Protocol response and security status
Kelp, the protocol behind the rsETH token, responded by placing the address that received the intercepted funds under a 24-hour pause [1]. The protocol stated that this was a precautionary, wallet-level measure intended to prevent the movement of the tokens while the situation is assessed [1]. 

Kelp has maintained that its core contracts remain secure and that rsETH is fully backed [1]. According to the protocol, standard operations including minting, withdrawals, and integrations are continuing to function normally while the team works with security experts to investigate the specific attack vector [1].

## What to watch
*   **Asset Recovery:** Monitor whether the address currently holding the $7.8 million in rsETH attempts to move the funds once the 24-hour pause imposed by Kelp expires.
*   **Protocol Updates:** Watch for further disclosures from Kelp regarding the specific custom module that served as the entry point for the exploit, which may impact other users of similar wallet configurations.

The incident underscores the dual nature of MEV bots, which can act as both a source of market friction and, as seen here, a mechanism that can inadvertently disrupt malicious exploits. Whether the intercepted funds are returned to the original victim or remain with the bot operator remains an open question.

## Sources
1. Cointelegraph — [ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address](https://cointelegraph.com/news/mev-bot-intercepts-77m-in-rseth-from-ethereum-wallet-exploit)
2. CoinCentral — [What Is an MEV Bot? How Yoink Intercepted a $7.8M rsETH Exploit on Ethereum](https://coincentral.com/what-is-an-mev-bot-how-yoink-intercepted-a-7-8m-rseth-exploit-on-ethereum/)
3. Coinpedia — [Ethereum Wallet Loses $7.8 Million in rsETH Exploit](https://coinpedia.org/news/ethereum-wallet-loses-7-8-million-in-rseth-exploit/)

---
Cite as: TrendWatcher, "MEV Bot Yoink Intercepts $7.8M rsETH Exploit on Ethereum", https://www.trendwatcher.in/article/44e2c47d-d415-4263-a46c-73981a390768
