An automated trading bot intercepted an attacker's attempt to extract $7.7 million in rsETH from an Ethereum Safe wallet, capturing the funds before the exploiter could claim them. Kelp, the protocol behind rsETH, then froze the receiving address as a precaution while it investigates.
An attacker exploited a custom module connected to an Ethereum Safe wallet in an attempt to extract roughly $7.7 million in rsETH, only for the funds to be intercepted by an MEV bot before the attacker could take control of them.
How the exploit unfolded
Blockchain security firm Blockaid said the attacker used a public keeper multicall to direct a custom Uniswap v4 liquidity module into an attacker-created hooked pool, where aEthrsETH was unwrapped into rsETH. Blockaid identified the affected wallet as a Safe belonging to an unidentified user and said about $7.73 million in rsETH had been lost at the time of its initial report.
An automated program known as Yoink then front-ran the attack, capturing the rsETH before the original exploiter could take control of the funds. Etherscan data shows Yoink transferred about 18.93 ETH, worth roughly $46,000, to an address labeled as a block builder in the same transaction.
Kelp freezes the receiving address
Kelp subsequently placed the address that received the funds under a 24-hour pause, temporarily preventing the tokens from being transferred. According to Kelp: "This is a precautionary, wallet-level measure only." The protocol said its smart contracts remain unaffected and that rsETH stays fully backed.
The protocol said minting, withdrawals and integrations were continuing normally while it worked with security experts to investigate the incident. The apparent attack vector involved the custom module connected to the victim's Safe, while Kelp said its own contracts were unaffected. Cointelegraph contacted Blockaid and Kelp for additional comment but had not received a response by publication.
Source: Cointelegraph.com News
Trading involves risk.