Incident Overview
In a significant incident involving Ethereum’s decentralized finance ecosystem, an automated Miner Extractable Value (MEV) bot, dubbed “Yoink,” thwarted an attacker attempting to abscond with approximately $7.7 million in rsETH. The attack targeted a custom Safe wallet module, prompting the intervention of the MEV bot just as the attacker was about to secure the stolen funds.
Details of the Attack
The chaos unfolded when the assailant manipulated a public keeper multicall, channeling liquidity through a specialized Uniswap v4 module into a tampered pool. This intricate move allowed the unwrapping of aEthrsETH into the sought-after rsETH. According to cybersecurity experts at Blockaid, the victim’s ether wallet was compromised, leading to the loss of rsETH before the exploiter could finalize the operation, highlighting the vulnerabilities in some Ethereum smart contracts.
Yoink’s Intervention
In a twist of fate, Yoink, which continuously scans for profitable transactions on the blockchain, front-ran the theft. The bot succeeded in snatching the rsETH ahead of the attacker, simultaneously moving around 18.93 ETH — equivalent to approximately $46,000 — to an address associated with block production within the same transaction.
Response from Kelp
In response to the incident, Kelp, the platform responsible for rsETH, acted swiftly to freeze the address receiving the diverted funds for 24 hours, a temporary measure intended to prevent any further transaction activity.
“This is strictly a precautionary, wallet-level action,”
stated Kelp in a communication, assuring users that their contracts remained intact and that rsETH was fully backed despite the upheaval.
Ongoing Measures
Moreover, Kelp announced that all other functionalities, including minting and withdrawals, would continue uninterrupted while the team collaborates with security professionals to probe the breach. They confirmed that their own smart contracts were not compromised, placing the responsibility on the custom module encapsulated within the victim’s Safe.
Conclusion
At the time of this report, Cointelegraph reached out to both Blockaid and Kelp for their insights but had yet to receive a response. This event underscores the ongoing challenges in the DeFi landscape, where sophisticated attacks continue to test the resilience of decentralized systems.