How Did the Attacker Target the Safe Wallet?
Why Did the Original Exploiter Lose the Funds?
The attack did not unfold as intended. The transaction was detected by an MEV bot known as Yoink, which front-ran the original exploiter and captured the rsETH within the same Ethereum block.MEV searchers monitor pending blockchain transactions and attempt to reorder or insert their own transactions when profitable opportunities appear. In this case, Yoink reproduced the extraction before the original attacker could complete it.On-chain data shows the bot moved roughly 2,882 rsETH, representing the overwhelming majority of the main extraction, to a separate address. Part of the transaction’s value was also converted, while approximately 18.93 ETH, worth about $46,000 at the time, was transferred to an address identified as a block builder.The intervention therefore prevented the original exploiter from taking direct control of most of the rsETH, but it does not by itself mean the victim has recovered the assets. Control instead shifted to another on-chain actor whose intentions have not been publicly established.
Investor Takeaway
Can Kelp Prevent the rsETH From Moving?
Kelp responded by placing the address holding most of the intercepted rsETH under a temporary 24-hour pause, preventing those tokens from moving while the incident is investigated.“This is a precautionary, wallet-level measure only,” Kelp said. “Kelp contracts are safe, rsETH remains fully backed.”The protocol said minting, withdrawals and integrations were continuing normally and that no broader action was required from rsETH users.The pause creates a limited containment window around the largest block of assets. On-chain tracking indicates approximately 2,882 rsETH from the primary transaction remained at the restricted receiving address after the MEV extraction. Some value involved in related transactions had already been routed elsewhere, meaning the wallet-level restriction does not necessarily cover every asset associated with the incident.The next question is whether the MEV operator cooperates with efforts to return the captured tokens, and what happens when Kelp’s temporary restriction expires.
What Does the Exploit Mean for Smart Wallet Security?
The attack illustrates a growing security problem around programmable wallets. Safe accounts can extend their functionality through modules that automate trading, liquidity management and other DeFi strategies, but those extensions may receive authority that bypasses normal owner-by-owner transaction approval.That means the security of a multisignature wallet can depend on more than its private keys and signing threshold. A poorly protected module with permission to execute transactions can become an alternative route into the wallet.For protocols and institutional users running automated DeFi strategies, reviewing callable functions, access controls and delegated execution rights may therefore be as important as protecting signer keys.The immediate rsETH exposure appears contained largely at the wallet level, while Kelp says its token remains fully backed. The unresolved issue is whether the roughly $7.7 million intercepted by Yoink can ultimately be returned to the affected Safe before the temporary restrictions are lifted.