MEV Bot Intercepted $7.7 Million Kelp Protocol Exploit

A bot successfully front-ran a malicious transaction targeting the Kelp Protocol in September 2026.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration of a translucent geometric monolith on a dark base, with glowing energy lines, representing digital blockchain security.
An automated MEV bot intercepted a $7.73 million exploit attempt targeting the Kelp Protocol in September 2026, preventing a significant loss of digital assets. AI Illustration. Upload story photo >

Live Poll

Do you trust automated MEV bots to help maintain security in decentralized financial markets?

An automated MEV bot identified and intercepted a $7.73 million rsETH exploit attempt on the Kelp Protocol. The incident occurred as an attacker attempted to utilize a custom Uniswap v4 liquidity module.

Why it matters

The intervention prevented a massive drain of digital assets, highlighting the complex role of front-running bots in blockchain security. Kelp Protocol responded by freezing the relevant address to secure the intercepted funds.

The bot transferred 18.93 ETH, valued at approximately $46,000, to a block builder to prioritize its transaction. The targeted rsETH liquidity module relied on Uniswap v4 hooked pools.

The players

Kelp Protocol

This is a decentralized finance platform that manages liquid restaking assets on the Ethereum blockchain.

Yoink

This is a Maximal Extractable Value (MEV) bot designed to identify and execute transactions in the mempool before other actors.

Uniswap v4

This is a decentralized exchange protocol that allows for the creation of custom liquidity pools and advanced modular features.

The details

The bot, known as Yoink, monitored the mempool and executed a transaction ahead of the attacker, who was using a public keeper multicall. Kelp Protocol has confirmed that its core smart contracts remain secure and unaffected by the attempt.

Timeline

  1. The exploit attempt took place in September 2026.

The Tech Race

This incident highlights the security challenges introduced by Uniswap v4 liquidity hooks in decentralized finance. It underscores how advanced programmable liquidity features can be leveraged by both developers and malicious actors in an evolving blockchain arms race.

Users of decentralized finance protocols should remain aware that platform pauses can temporarily restrict the movement of funds during security incidents. This event also highlights the ongoing reliance on MEV bots for the automated defense of blockchain liquidity.

The takeaway

The successful interception shows that automated defensive strategies can mitigate risks, even in highly volatile exploit attempts. Investors in decentralized platforms should monitor protocol security updates and temporary administrative freezes following any suspicious activity.

Further reading

For more information on current digital threats, visit our Cybersecurity section.

Source note: This article includes information reported by The Cryptonomist.

Live Poll

Do you trust automated MEV bots to help maintain security in decentralized financial markets?