MEV Bot Intercepted $7.7 Million Kelp Protocol Exploit

A front-running bot thwarted a $7.73 million rsETH theft attempt on the Kelp Protocol via Ethereum in September 2026.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration of a geometric lattice structure flowing into a central containment vessel, representing blockchain security intervention.
An automated MEV bot successfully front-ran a malicious transaction targeting the Kelp Protocol, intercepting a $7.73 million rsETH exploit attempt on Tuesday. AI Illustration. Upload story photo >

Live Poll

Do you trust automated MEV bots to help maintain security in decentralized financial markets?

An MEV bot named Yoink successfully front-ran a malicious transaction targeting the Kelp Protocol to intercept a $7.73 million rsETH drain. The protocol has since placed the address holding the recovered funds under a 24-hour pause to prevent further movement.

Why it matters

This incident highlights how automated MEV bots—programs that monitor pending blockchain transactions—increasingly function as reflexive security agents in DeFi ecosystems. The event demonstrates the inherent transparency of public mempools where attackers and arbitrageurs compete for state changes in real time.

The attacker attempted to use a custom Uniswap v4 liquidity module to siphon assets, but the Yoink bot detected the exploit in the mempool. By paying 18.93 ETH to a block builder, the bot prioritized its own transaction to execute before the attacker's malicious call.

The players

Kelp Protocol

A liquid restaking protocol built on Ethereum that manages diversified yield-bearing assets.

Uniswap v4

A decentralized exchange architecture featuring hooks that allow developers to create custom liquidity pools.

The details

The exploit relied on a public keeper multicall, a function designed to trigger contract actions, to direct liquidity into a manipulated pool. The Yoink bot monitored the mempool—the waiting area for unconfirmed transactions—and successfully front-ran the attacker by submitting a higher-fee transaction that forced the network to process the bot's intervention first. Kelp confirmed its core smart contracts remain unaffected by the attempted injection of the custom module.

Timeline

  1. The rsETH exploit attempt occurred in September 2026.

The Tech Race

This exploit marks a testing ground for the security of advanced Uniswap v4 hook implementations which are designed to increase DeFi flexibility. It mirrors ongoing competition between developers building programmable liquidity and attackers exploiting the mempool to capture value before it settles.

Users with funds in the Kelp Protocol are impacted by the 24-hour pause on the specific address holding the intercepted assets. While core smart contracts were not compromised, the event highlights the heightened risk associated with protocols utilizing custom liquidity modules.

The takeaway

This event confirms that while MEV bots often capture value for themselves, they can effectively act as a secondary defensive layer in the mempool. Watch for future updates from Kelp Protocol regarding the final disposition of the recovered $7.73 million in rsETH.

Further reading

For more on the security of decentralized finance protocols, visit our Cybersecurity section.

Source note: This article includes information reported by The Cryptonomist.

Live Poll

Do you trust automated MEV bots to help maintain security in decentralized financial markets?