$7.8 Million Crypto Heist Backfires as Rival Bot Steals the Loot
An attacker drained roughly $7.8 million worth of rsETH tokens from an Ethereum Safe wallet by abusing a custom module the wallet's owner had approved. Security firm Blockaid confirmed the wallet's core security was not at fault; instead, a Multicall helper linked to a Uniswap v4 liquidity module treated certain self-referencing calls as automatically authorised, letting the attacker push instructions through as if they came from the wallet itself.
Before the attacker could collect the stolen funds, an automated trading bot known as Yoink spotted the pending transaction in the public mempool and paid roughly $46,000 to have its own transaction processed first in the same block. This let the bot capture the funds instead of the original attacker, redirecting about 2,882 rsETH to a new address.
Restaking protocol Kelp DAO responded quickly, freezing the address that received the funds within two hours and placing it under a 24-hour pause as a precaution. The protocol confirmed that rsETH remains fully backed and that normal minting and withdrawal operations were not affected by the incident.