By Interestana AI Editorial — AI-drafted, human-overseen. How we report
MEV Bot Captures $7.7M in ETH Exploit; Kelp Freezes Address

An exploit targeting a custom Safe module within the Kelp Decentralized Autonomous Organization (DAO) ecosystem was thwarted by a Maximal Extractable Value (MEV) bot, which successfully captured approximately $7.7 million worth of stolen staked Ether (stETH) derivatives. The MEV bot, identified as "Yoink," executed a front-running strategy, intercepting the illicitly obtained staked Ether (rsETH) before the attacker could finalize their withdrawal. This intervention prevented the attacker from profiting from the exploit. Following the incident, Kelp DAO took action to freeze the address that was intended to receive the stolen funds, effectively immobilizing the assets and preventing further movement. The exploit targeted a specific custom Safe module, a feature within the Safe (formerly Gnosis Safe) multi-signature wallet infrastructure that allows for programmable smart contract interactions. Safe modules are designed to enhance functionality and automate actions, but they can also introduce new attack vectors if not properly secured. Kelp DAO is a liquid staking protocol that allows users to stake their Ether and receive liquid derivatives, such as rsETH, which can then be used in other DeFi applications. The protocol aims to improve capital efficiency within the Ethereum ecosystem. MEV bots, like "Yoink," operate by monitoring the Ethereum mempool for pending transactions and strategically placing their own transactions to profit from the order of execution. In this case, "Yoink" identified the malicious transaction and its intended outcome, then submitted a transaction with a higher gas fee to ensure it was processed first, thereby capturing the target assets. The incident highlights the ongoing cat-and-mouse game between exploiters and defensive actors within the decentralized finance (DeFi) space, particularly concerning the complex interplay of smart contracts, MEV, and security protocols. The swift action by Kelp DAO to freeze the address demonstrates a proactive security response, though the initial exploit attempt underscores the persistent risks associated with smart contract vulnerabilities and the sophisticated tactics employed by malicious actors. The total value captured by the MEV bot, $7.7 million, represents a significant sum, indicating the substantial potential rewards for successful exploits and the equally substantial incentives for MEV bots to intervene.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.