Kelp DAO, the protocol behind the liquid staking token rsETH on Ethereum, narrowly avoided a multi-million euro theft on September 15, 2026, after an automated bot beat an attacker to the punch.
According to security firm Blockaid, which first identified the attack vector, an attacker attempted to exploit a custom Safe module linked to an Ethereum wallet connected to Kelp DAO. The exploit worked by redirecting a Uniswap v4 liquidity module to a custom "hooked" pool, where aEthrsETH tokens were unwrapped into rsETH. Blockaid's initial estimate put the amount at risk at approximately $7.73 million.
Before the attacker could complete the theft, an automated MEV bot named Yoink front-ran the transaction, intercepting approximately $7.7 million in rsETH. In doing so, Yoink sent roughly 18.93 ETH, equal to about $46,000, to a block builder address, a cost typical of transactions competing for priority inclusion on the Ethereum network.
Kelp DAO's response
Following the incident, Kelp DAO paused the receiving address linked to the exploit attempt for 24 hours as a precaution while it investigated the matter alongside external security experts. The protocol described the move as "una misura precauzionale, solo a livello di wallet," stressing that the pause applied only at the wallet level and not to its underlying contracts.
Kelp DAO further maintained that its core infrastructure was unaffected, stating that "i contratti di Kelp sono sicuri, rsETH resta interamente garantito." The protocol confirmed that minting, withdrawals, and integrations with other services continued to operate normally throughout the investigation.
A reminder of MEV's dual role
The episode illustrates how automated bots operating in Ethereum's transaction ordering layer can, in certain circumstances, work against attackers rather than exploit users. Yoink's interception did not prevent the initial attack vector from being exposed, but it did stop the specific attacker from walking away with the funds.
For European holders of rsETH, who rely on Kelp DAO as one of several liquid staking providers active on Ethereum, the incident underscores the persistent exposure of smart contract modules and third-party integrations such as Safe and Uniswap v4 to novel exploitation techniques, even when a protocol's own contracts remain secure.




