PeckShieldAlert Flags $7.81M rsETH Exploit Front-Run by MEV Bot

A security alert attributed to PeckShieldAlert says an MEV bot front-ran a roughly $7.81 million rsETH exploit on Ethereum, adding another example of how fast-moving mempool activity can determine who ends up with assets during an attack.
#PeckShieldAlert MEV bot yoink front-runs a ~$7.81M $rsETH exploit on Ethereum pic.twitter.com/vAJwsCOfsQ
— PeckShieldAlert (@PeckShieldAlert) September 15, 2026
The claim points to a transaction sequence in which a malicious attempt involving rsETH was detected and then overtaken before completion. In that version of events, the MEV bot was the party that captured the value rather than the original attacker.
The broader rsETH incident has been described by secondary coverage as involving a wallet and a custom module path tied to the asset, but the exact details of the exploit and the full scope of losses are not fully established in the material available here. What is clear is that the reported front-run happened in the middle of a security event, not as a routine arbitrage trade.
MEV activity can change who captures the value
MEV bots watch pending Ethereum transactions and can react before those transactions are finalized. In exploit settings, that can mean a bot arrives first, intercepts the value flow and leaves the original attacker without the proceeds they expected to take.
That is the key distinction in this case: the reported $7.81 million figure is tied to the exploit attempt, while the front-run describes the bot’s intervention in the transaction flow. The available material does not show whether the bot’s capture was fully realized in the same way as a normal market trade, but it does indicate the bot got ahead of the exploit path.
Security incidents involving liquid-staking or restaking assets often move quickly because those tokens can be large enough to attract both attackers and opportunistic bots. Here, the reported rsETH exposure appears to have been visible in the mempool long enough for an MEV system to react.
Further confirmation on the exact exploit path, the wallet involved and whether any underlying protocol contracts were affected has not been established in the material available for this report.






