Trending
    CryptoVery High

    Kelp DAO Exploit Results in $293 Million Loss and $6 Billion Decline in Aave TVL

    Section editor: ·Very High3 articles covering this·2 news sources·Updated a month ago·World
    Share:
    Kelp DAO Exploit Results in $293 Million Loss and $6 Billion Decline in Aave TVL

    Here's what it means for you.

    If you’re involved in decentralized finance (DeFi), this incident underscores the importance of understanding cross-chain vulnerabilities and their potential impact on your investments.

    Why it matters

    This exploit reveals critical systemic risks in cross-chain infrastructure that could affect the stability of DeFi markets globally.

    What happened (in 30 seconds)

    • Kelp DAO was exploited for approximately $293 million on April 18, 2026, due to a vulnerability in its LayerZero-powered bridge.
    • Aave's total value locked (TVL) dropped by $6 billion as mass withdrawals followed the exploit, highlighting collateral dependencies in lending markets.
    • Emergency measures were implemented across affected protocols, freezing markets and pausing contracts to mitigate further losses.

    The context you actually need

    • Kelp DAO provides liquid restaking for ETH via rsETH, integrated with EigenLayer and utilizing LayerZero's OFT bridge for cross-chain transfers across over 20 networks.
    • The exploit involved spoofing a cross-chain message, tricking the bridge into releasing unbacked rsETH to an attacker-controlled address funded via Tornado Cash.
    • This incident is part of a broader trend of vulnerabilities in DeFi, with multiple exploits occurring in 2026, including a $285 million incident involving the Drift Protocol.

    What's really happening

    On April 18, 2026, at 17:35 UTC, an attacker initiated a sophisticated exploit of the Kelp DAO's LayerZero cross-chain bridge. By spoofing a cross-chain message, the attacker drained 116,500 rsETH tokens, valued at approximately $293 million, from the bridge. This exploit was particularly alarming as it represented 18% of the circulating supply of rsETH, raising immediate concerns about the stability of Kelp DAO and its associated protocols.

    In response to the exploit, Kelp's emergency multisig team acted swiftly, freezing core contracts at 18:21 UTC. This decisive action thwarted two subsequent attempts by the attacker to drain an additional $100 million. However, the damage was already done. The attacker had already deposited the stolen rsETH as collateral on Aave V3 Ethereum, borrowing around $200 million in wrapped ETH. This maneuver created approximately $196 million in bad debt on Aave, prompting the platform to freeze rsETH markets on both V3 and V4.

    The fallout was immediate and severe. Aave's total value locked (TVL) plummeted from $26.4 billion to $20 billion, a staggering decline of $6.6 billion. The AAVE token, which is integral to the governance and utility of the Aave platform, saw a decline of 16-20%, dropping to around $92. LayerZero's ZRO token also suffered, falling by 30%. This incident not only highlighted the vulnerabilities in cross-chain infrastructure but also underscored the collateral dependencies that exist within lending markets, where the failure of one protocol can have cascading effects on others.

    The exploit has prompted a wave of precautionary measures across the DeFi landscape. Affected protocols, including Lido Finance and Ethena, have paused operations to assess risks and prevent further losses. Kelp DAO, Aave, and LayerZero have initiated joint investigations to understand the exploit's mechanics and to enhance security measures moving forward. The decentralized nature of these platforms means that there has been no centralized governmental response, but the industry is feeling the impact nonetheless, with a contraction of approximately $10 billion in DeFi TVL across the board.

    Who feels it first (and how)

    • DeFi investors: Those holding AAVE or rsETH tokens face immediate financial losses due to price declines.
    • Liquidity providers: Users providing liquidity to affected protocols may see reduced returns or losses due to frozen markets.
    • Developers and protocol teams: Increased scrutiny and pressure to enhance security measures and address vulnerabilities in their platforms.
    • Regulatory bodies: As incidents like this gain attention, regulators may increase oversight on DeFi protocols, impacting operational frameworks.

    What to watch next

    • Investigations outcomes: The results of ongoing investigations by Kelp DAO, Aave, and LayerZero will provide insights into the exploit's mechanics and potential security improvements.
    • Market recovery trends: Monitor how quickly Aave and other affected protocols can restore confidence and liquidity in their markets.
    • Regulatory developments: Watch for any new regulations or guidelines that may emerge in response to this incident, which could reshape the DeFi landscape.
    Known:

    The exploit resulted in a $293 million loss for Kelp DAO and a $6 billion decline in Aave's TVL.

    Likely:

    Increased scrutiny and precautionary measures across DeFi protocols will follow as the industry seeks to mitigate similar risks.

    Unclear:

    The long-term impact on investor confidence in DeFi and the potential for regulatory changes remains uncertain.

    Frequently Asked Questions

    Why it matters?
    This exploit reveals critical systemic risks in cross-chain infrastructure that could affect the stability of DeFi markets globally.
    What happened (in 30 seconds)?
    Kelp DAO was exploited for approximately $293 million on April 18, 2026, due to a vulnerability in its LayerZero-powered bridge. Aave's total value locked (TVL) dropped by $6 billion as mass withdrawals followed the exploit, highlighting collateral dependencies in lending markets. Emergency measures were implemented across affected protocols, freezing markets and pausing contracts to mitigate further losses.
    What's really happening?
    On April 18, 2026, at 17:35 UTC, an attacker initiated a sophisticated exploit of the Kelp DAO's LayerZero cross-chain bridge. By spoofing a cross-chain message, the attacker drained 116,500 rsETH tokens, valued at approximately $293 million, from the bridge. This exploit was particularly alarming as it represented 18% of the circulating supply of rsETH, raising immediate concerns about the stability of Kelp DAO and its associated protocols. In response to the exploit, Kelp's emergency multisig
    Who feels it first (and how)?
    DeFi investors: Those holding AAVE or rsETH tokens face immediate financial losses due to price declines. Liquidity providers: Users providing liquidity to affected protocols may see reduced returns or losses due to frozen markets. Developers and protocol teams: Increased scrutiny and pressure to enhance security measures and address vulnerabilities in their platforms. Regulatory bodies: As incidents like this gain attention, regulators may increase oversight on DeFi protocols, impacting o
    What to watch next?
    Investigations outcomes: The results of ongoing investigations by Kelp DAO, Aave, and LayerZero will provide insights into the exploit's mechanics and potential security improvements. Market recovery trends: Monitor how quickly Aave and other affected protocols can restore confidence and liquidity in their markets. Regulatory developments: Watch for any new regulations or guidelines that may emerge in response to this incident, which could reshape the DeFi landscape.
    3 Articles
    Crypto Briefing

    KelpDAO exploit causes $10.5B drop in DeFi TVL, AAVE suspends rsETH markets

    The KelpDAO exploit has led to a significant $10.5 billion drop in the total value locked (TVL) in decentralized finance (DeFi), prompting AAVE to suspend its rsETH markets. This incident highlights the vulnerabilities present in DeFi platforms, rais...

    Crypto Briefing

    AAVE TVL plummets $6B after Kelp DAO hack exploits LayerZero bridge flaw

    AAVE's total value locked (TVL) has plummeted by $6 billion following a significant hack of Kelp DAO, which exploited a flaw in the LayerZero bridge. The breach has raised alarms about the security vulnerabilities inherent in decentralized finance (D...

    CoinDesk

    Aave sees $6 billion deposit drop as Kelp hack exposes structural risk for DeFi lender

    Aave has experienced a significant drop in deposits, losing approximately $6 billion, following a hack that exploited drained rsETH as collateral to borrow wrapped ether. This incident has resulted in a 16% decline in the value of the AAVE token as t...