Trending
    CryptoVery High

    Kelp DAO Exploit Results in $292 Million Loss and Highlights DeFi Vulnerabilities

    Section editor: ·Very High9 articles covering this·5 news sources·Updated a month ago·World
    Share:
    Kelp DAO Exploit Results in $292 Million Loss and Highlights DeFi Vulnerabilities

    Here's what it means for you.

    If you’re involved in DeFi, this exploit underscores the importance of understanding the risks associated with cross-chain mechanisms.

    Why it matters

    This incident reveals critical vulnerabilities in decentralized finance (DeFi) systems, particularly in cross-chain asset transfers.

    What happened (in 30 seconds)

    • An attacker exploited Kelp DAO's LayerZero bridge, minting 116,500 unbacked rsETH tokens worth approximately $292 million.
    • The exploit led to a $6 billion decline in Aave's total value locked (TVL) as the attacker used the unbacked tokens as collateral to borrow real ETH.
    • Kelp DAO paused its core contracts 46 minutes after the exploit was detected, but the damage had already triggered market freezes across multiple platforms.

    The context you actually need

    • Kelp DAO is a liquid restaking protocol that issues rsETH, a yield-bearing derivative of Ethereum, using a single-signer bridge model for efficiency.
    • The exploit occurred amid a surge in DeFi incidents in 2026, including a $285 million hack of the Drift protocol just weeks prior.
    • State-sponsored threats are increasingly suspected in DeFi hacks, with the Lazarus Group, linked to North Korea, being a prime suspect in this case.

    What's really happening

    On April 18, 2026, at 17:35 UTC, the Kelp DAO exploit unfolded as an attacker manipulated the protocol's role as a LayerZero bridge verifier. This single-signer model allowed the unauthorized minting of 116,500 rsETH tokens, which represented 18% of the circulating supply. The exploit was executed by depositing these unbacked tokens into lending platforms, primarily Aave V3, where the attacker borrowed $236 million in real ETH.

    The implications of this exploit are profound. Kelp DAO's reliance on a single-party verification model created a critical vulnerability that was exploited, leading to a significant loss of trust in DeFi protocols. The immediate aftermath saw Aave's total value locked plummet by $6 billion, as the market reacted to the bad debt created by the unbacked collateral. This incident not only stranded wrapped ETH across 20 different chains but also triggered a freeze on rsETH markets by Aave and Compound, further exacerbating the situation.

    The exploit highlights the systemic risks inherent in cross-chain mechanisms, particularly those that utilize single-signer configurations. As DeFi continues to grow, the interconnectedness of these protocols means that vulnerabilities in one can have cascading effects across the entire ecosystem. The Kelp DAO incident serves as a stark reminder of the need for robust security measures and diversified verification processes to mitigate risks.

    In the wake of the exploit, reactions from industry leaders were swift. Michael Egorov of Curve Finance criticized the reliance on single-party trust, emphasizing that such vulnerabilities can lead to catastrophic failures. Charles Guillemet from Ledger predicted that 2026 could be remembered as DeFi's worst year for hacks, eroding confidence in these protocols. Meanwhile, Justin Sun suggested negotiating with the hacker, indicating a growing concern over the implications of such exploits on the broader market.

    Who feels it first (and how)

    • DeFi protocol users: Individuals who have invested in or utilized Kelp DAO, Aave, or other affected platforms may face immediate financial losses.
    • Lending platforms: Aave and Compound are directly impacted, with significant drops in their total value locked and market activity.
    • Investors in rsETH: Holders of rsETH tokens are experiencing market freezes and potential losses due to the exploit.
    • Developers and protocol creators: Those involved in building DeFi solutions may face increased scrutiny and pressure to enhance security measures.

    What to watch next

    • Regulatory responses: Watch for potential regulatory actions aimed at enhancing security protocols in DeFi, which could reshape the landscape.
    • Market recovery indicators: Monitor how quickly Aave and other affected platforms can recover their total value locked and restore user confidence.
    • Security audits: Keep an eye on the frequency and depth of security audits conducted by DeFi protocols in the aftermath of this exploit, as they may indicate a shift towards more robust security practices.
    Known:

    The Kelp DAO exploit resulted in a $292 million loss and a $6 billion decline in Aave's total value locked.

    Likely:

    Increased scrutiny and regulatory measures will emerge in response to the exploit, affecting how DeFi protocols operate.

    Unclear:

    The long-term impact on user trust in DeFi protocols and whether new security measures will effectively mitigate future risks.

    Frequently Asked Questions

    Why it matters?
    This incident reveals critical vulnerabilities in decentralized finance (DeFi) systems, particularly in cross-chain asset transfers.
    What happened (in 30 seconds)?
    An attacker exploited Kelp DAO's LayerZero bridge, minting 116,500 unbacked rsETH tokens worth approximately $292 million. The exploit led to a $6 billion decline in Aave's total value locked (TVL) as the attacker used the unbacked tokens as collateral to borrow real ETH. Kelp DAO paused its core contracts 46 minutes after the exploit was detected, but the damage had already triggered market freezes across multiple platforms.
    What's really happening?
    On April 18, 2026, at 17:35 UTC, the Kelp DAO exploit unfolded as an attacker manipulated the protocol's role as a LayerZero bridge verifier. This single-signer model allowed the unauthorized minting of 116,500 rsETH tokens, which represented 18% of the circulating supply. The exploit was executed by depositing these unbacked tokens into lending platforms, primarily Aave V3, where the attacker borrowed $236 million in real ETH. The implications of this exploit are profound. Kelp DAO's reliance
    Who feels it first (and how)?
    DeFi protocol users: Individuals who have invested in or utilized Kelp DAO, Aave, or other affected platforms may face immediate financial losses. Lending platforms: Aave and Compound are directly impacted, with significant drops in their total value locked and market activity. Investors in rsETH: Holders of rsETH tokens are experiencing market freezes and potential losses due to the exploit. Developers and protocol creators: Those involved in building DeFi solutions may face increased scrutiny
    What to watch next?
    Regulatory responses: Watch for potential regulatory actions aimed at enhancing security protocols in DeFi, which could reshape the landscape. Market recovery indicators: Monitor how quickly Aave and other affected platforms can recover their total value locked and restore user confidence. Security audits: Keep an eye on the frequency and depth of security audits conducted by DeFi protocols in the aftermath of this exploit, as they may indicate a shift towards more robust security practices.
    9 Articles
    Crypto Briefing

    $280M KelpDAO exploit raises DeFi security concerns, impacts Solana markets

    The KelpDAO exploit has resulted in a significant loss of approximately $280 million, raising serious concerns about the security vulnerabilities within decentralized finance (DeFi) infrastructure and its potential impact on investor confidence and m...

    Bitcoinist

    What The Kelp DAO’s $292 Million Hack Means For XRP Holders Earning Yield

    A significant security breach occurred at Kelp DAO over the weekend, where an attacker exploited the LayerZero-powered bridge, resulting in the loss of approximately $292 million in tokens. This incident marks one of the largest hacks in decentralize...

    Crypto News

    Kelp DAO blames LayerZero defaults for $290m rsETH bridge disaster

    Kelp DAO has attributed a significant security breach, resulting in a loss of approximately $290 million from its rsETH bridge, to LayerZero's default single-validator setup. This incident has sparked a blame game between Kelp DAO and LayerZero, with...

    CoinDesk

    Kelp DAO claims LayerZero’s 'default' settings are what actually caused the massive $290 million disaster

    Kelp DAO has claimed that the recent $290 million exploit of its liquid restaking protocol was caused by LayerZero's default settings, which allowed a compromised verifier to drain funds. The incident has raised significant concerns about the securit...

    Cointelegraph

    LayerZero says Kelp setup enabled exploit, as Aave loss questions mount

    LayerZero has reported that the recent $290 million exploit of KelpDAO was facilitated by a setup that did not adhere to multi-verifier recommendations, allowing attackers to compromise the system. This incident has raised significant concerns regard...

    Bitcoinist

    LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit

    LayerZero has addressed the recent $290 million exploit of KelpDAO, detailing how the incident unfolded and asserting that it was not a failure of their protocol. The exploit, which drained significant funds from KelpDAO's LayerZero-powered bridge, h...

    Crypto Briefing

    KelpDAO bridge hack drains $292M in largest DeFi exploit of 2026

    The KelpDAO bridge hack has resulted in a staggering loss of $292 million, marking it as the largest exploit in decentralized finance (DeFi) for 2026. This incident has raised alarms about the security vulnerabilities inherent in interconnected crypt...

    CoinDesk

    The $292 million Kelp exploit: how it happened, and what it means for DeFi

    The Kelp exploit has resulted in a staggering loss of approximately $293 million, marking a significant breach in the decentralized finance (DeFi) sector. This incident has raised alarms about the vulnerabilities inherent in interconnected DeFi platf...

    Cointelegraph

    Kelp restaking platform exploited, $293M drained in attack

    The Kelp restaking platform has been exploited, resulting in a significant loss of approximately $293 million. This attack has triggered a