MEV Bot Intercepted $7.7 Million Kelp Protocol Exploit
A front-running bot thwarted a $7.73 million rsETH theft attempt on the Kelp Protocol via Ethereum in September 2026.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust automated MEV bots to help maintain security in decentralized financial markets?
An MEV bot named Yoink successfully front-ran a malicious transaction targeting the Kelp Protocol to intercept a $7.73 million rsETH drain. The protocol has since placed the address holding the recovered funds under a 24-hour pause to prevent further movement.
Why it matters
This incident highlights how automated MEV bots—programs that monitor pending blockchain transactions—increasingly function as reflexive security agents in DeFi ecosystems. The event demonstrates the inherent transparency of public mempools where attackers and arbitrageurs compete for state changes in real time.
The attacker attempted to use a custom Uniswap v4 liquidity module to siphon assets, but the Yoink bot detected the exploit in the mempool. By paying 18.93 ETH to a block builder, the bot prioritized its own transaction to execute before the attacker's malicious call.
The players
Kelp Protocol
A liquid restaking protocol built on Ethereum that manages diversified yield-bearing assets.
Uniswap v4
A decentralized exchange architecture featuring hooks that allow developers to create custom liquidity pools.
The details
The exploit relied on a public keeper multicall, a function designed to trigger contract actions, to direct liquidity into a manipulated pool. The Yoink bot monitored the mempool—the waiting area for unconfirmed transactions—and successfully front-ran the attacker by submitting a higher-fee transaction that forced the network to process the bot's intervention first. Kelp confirmed its core smart contracts remain unaffected by the attempted injection of the custom module.
Timeline
The rsETH exploit attempt occurred in September 2026.
The Tech Race
This exploit marks a testing ground for the security of advanced Uniswap v4 hook implementations which are designed to increase DeFi flexibility. It mirrors ongoing competition between developers building programmable liquidity and attackers exploiting the mempool to capture value before it settles.
Users with funds in the Kelp Protocol are impacted by the 24-hour pause on the specific address holding the intercepted assets. While core smart contracts were not compromised, the event highlights the heightened risk associated with protocols utilizing custom liquidity modules.
The takeaway
This event confirms that while MEV bots often capture value for themselves, they can effectively act as a secondary defensive layer in the mempool. Watch for future updates from Kelp Protocol regarding the final disposition of the recovered $7.73 million in rsETH.
Further reading
For more on the security of decentralized finance protocols, visit our Cybersecurity section.
Source note: This article includes information reported by The Cryptonomist.
Live Poll
Do you trust automated MEV bots to help maintain security in decentralized financial markets?






