A hacker’s attempt to drain a Safe wallet took an unexpected twist: after spotting a vulnerability in a third-party module, the attacker tried to move out about 2,900 rsETH (roughly $7.8 million). But before they could pull it off, MEV bot Yoink swooped in and front-ran the exploit, snatching almost the whole bag for itself.

What Happened

The exploit targeted a third-party module connected to a Safe wallet, aiming to steal around 2,900 rsETH—the token issued by Kelp DAO. Neither Kelp DAO nor Safe itself were compromised in the hack.

How the MEV Bot Yoink Got Involved

MEV bot Yoink spotted the malicious transaction and ran the same exploit before the original hacker could, grabbing nearly all the funds. As of press time, the wallet’s owner hasn’t gotten their money back, and the Yoink dev hasn’t made any public move to return the stolen rsETH.

Kelp DAO’s Response and User Risks

Kelp DAO temporarily froze the bot’s address. The security team also urged users to revoke approvals on their contracts for now. Anyone who’s interacted with the protocol could be at risk until the vulnerability gets patched.