A maximal extractable value (MEV) bot named "Yoink" intercepted an attacker mid-heist, front-running the exploit and capturing $7.7 million in stolen rsETH tokens before Kelp DAO could respond. The incident reveals both the predatory nature of MEV extraction and the speed of on-chain defense mechanisms.
The attack began when someone attempted to exploit a custom Safe module tied to Kelp DAO's liquid restaking protocol. The attacker stood to drain a substantial portion of rsETH from the protocol contract. But Yoink, an MEV bot constantly monitoring the mempool for profitable transactions, spotted the attack transaction before it executed. Instead of watching the exploit succeed, Yoink front-ran it, submitting its own transaction ahead in the block order and capturing the stolen tokens worth $7.7 million.
This is where the story gets interesting. MEV bots typically prey on regular traders through sandwich attacks and liquidations. Here, Yoink's predatory behavior actually worked against a malicious actor. The bot extracted value from the thief rather than the protocol or users directly. It's a rare case where the parasite bit the bigger predator.
Kelp DAO moved quickly after detecting the situation. The team identified the address receiving the stolen rsETH and froze it before the attacker or the MEV bot could move the tokens further. This freeze-and-pause mechanism speaks to Kelp's administrative controls over the token. While such controls enable rapid response to exploits, they also highlight the centralized governance aspects present even in decentralized finance protocols.
The sequence of events matters here. The attacker accessed the Safe module, likely through a permissions misconfiguration or unpatched vulnerability. They initiated the exploit and broadcast it to the network. Yoink's infrastructure spotted the transaction in the mempool, recognized its profit potential, and submitted a competing transaction with higher gas fees. Miners prioritized the higher-fee transaction, executing Yoink's grab before the original attacker's code could transfer the rsETH. Then Kelp froze the address where Yoink had deposited the funds.
This creates an unusual outcome. The attacker walks away empty-handed. Yoink captured the tokens but can't move them due to Kelp's freeze. Kelp DAO retains the ability to recover the funds or distribute them. No end users lost assets directly, though the protocol was exposed to an exploit it should have detected earlier.
The incident raises questions about Safe module security and third-party integrations. Many protocols build custom modules on top of Safe's architecture to enable specific functionality. These modules introduce additional surface area for vulnerabilities. Kelp's team will need to audit whatever Safe module the attacker exploited and patch it before unfreezing operations.
For the broader MEV ecosystem, this shows how bots operate without moral constraints. Yoink isn't heroic for stopping the attacker. It simply recognized a profitable opportunity and executed on it faster than competitors. The fact that stopping a hack also happened to be profitable is incidental to its design.
Kelp DAO will likely recover the funds and work toward resolving the underlying vulnerability. The incident demonstrates both the risks of custom contract modules and the omnipresence of MEV extraction across all transaction types, from routine swaps to stealing protocol assets.
