Trending

    $292 Million KelpDAO rsETH Bridge Exploit Exposes Cross-Chain Security Flaws

    Section editor: ·Moderate12 articles covering this·6 news sources·Updated a month ago·World
    Share:
    $292 Million KelpDAO rsETH Bridge Exploit Exposes Cross-Chain Security Flaws

    Here's what it means for you.

    If you’re involved in decentralized finance (DeFi), this exploit underscores the critical need for robust security measures in cross-chain operations.

    Why it matters

    This incident reveals significant vulnerabilities in cross-chain bridge security, potentially destabilizing the entire DeFi ecosystem.

    What happened (in 30 seconds)

    • On April 18, 2026, the KelpDAO rsETH bridge was exploited for approximately $292 million due to a vulnerability in its LayerZero infrastructure.
    • The attacker minted 116,500 unbacked rsETH tokens by compromising a single-verifier configuration, impacting Ethereum and Arbitrum networks.
    • Immediate reactions included contract pauses by KelpDAO and market freezes by Aave, leading to a $13 billion decline in total value locked across DeFi protocols within 48 hours.

    The context you actually need

    • KelpDAO operates a liquid restaking protocol that issues rsETH, backed by EigenLayer, and utilizes LayerZero for cross-chain bridging across over 20 networks.
    • The exploit stemmed from a misconfigured Decentralized Verifier Network (DVN) in LayerZero's infrastructure, which was vulnerable to single-point compromise.
    • This incident follows a series of DeFi hacks, including the $285 million Drift Protocol hack on Solana, raising scrutiny on the security of restaking and bridge mechanisms.

    What's really happening

    At approximately 17:35 UTC on April 18, 2026, the attacker executed a sophisticated exploit by sending a malicious LayerZero packet (nonce 308). This attack leveraged the 1/1 DVN configuration, which allowed the attacker to forge verification and mint 116,500 unbacked rsETH tokens valued at $292 million on Ethereum. The funds were then deposited as collateral on major lending platforms like Aave V3, Compound V3, and Euler, enabling borrows exceeding $236 million in Wrapped Ether (WETH) and other assets.

    The laundering process involved using Tornado Cash, with the stolen funds split across Ethereum ($178 million) and Arbitrum ($72 million). KelpDAO's pauser multisig activated roughly 46 minutes post-exploit, freezing rsETH contracts and thwarting two subsequent drain attempts totaling $100 million.

    In the aftermath, KelpDAO and LayerZero confirmed investigations into the breach, attributing it to KelpDAO's configuration and tactics associated with the Lazarus Group, which is suspected of using compromised RPC nodes and DDoS attacks. Aave responded by freezing rsETH markets, while Lido paused deposits, leading to panic withdrawals and a significant drop in Aave's total value locked (TVL), which fell from $26.4 billion to $20 billion.

    The incident has sparked a wave of fear within the DeFi community, with sentiments echoing that "DeFi is dead." This reflects a broader concern about the security of decentralized finance platforms, especially in light of rising attacks linked to North Korean entities. The decentralized nature of these platforms means that there are no governmental interventions, leaving users to navigate the fallout independently.

    Who feels it first (and how)

    • DeFi investors: Immediate losses from liquidity crunches and asset devaluations.
    • Lending platforms: Significant drops in total value locked and operational disruptions.
    • Developers and security teams: Increased scrutiny and pressure to enhance security measures across protocols.
    • UAE crypto investors: Indirect effects from DeFi TVL declines and AAVE price drops, amplifying local market volatility.

    What to watch next

    • Security audits: Increased demand for comprehensive security audits across DeFi protocols will likely emerge as a response to this exploit.
    • Market reactions: Watch for further declines in total value locked across DeFi platforms and potential shifts in user trust towards centralized exchanges.
    • Regulatory developments: Although no governmental interventions have been noted, increased scrutiny from regulators could reshape the landscape of decentralized finance.
    Known:

    The exploit resulted in a $292 million loss and a $13 billion decline in total value locked across DeFi protocols.

    Likely:

    There will be heightened scrutiny and demand for improved security measures in cross-chain operations.

    Unclear:

    The long-term impact on user trust in DeFi platforms and the potential for regulatory responses remains uncertain.

    Frequently Asked Questions

    Why it matters?
    This incident reveals significant vulnerabilities in cross-chain bridge security, potentially destabilizing the entire DeFi ecosystem.
    What happened (in 30 seconds)?
    On April 18, 2026, the KelpDAO rsETH bridge was exploited for approximately $292 million due to a vulnerability in its LayerZero infrastructure. The attacker minted 116,500 unbacked rsETH tokens by compromising a single-verifier configuration, impacting Ethereum and Arbitrum networks. Immediate reactions included contract pauses by KelpDAO and market freezes by Aave, leading to a $13 billion decline in total value locked across DeFi protocols within 48 hours.
    What's really happening?
    At approximately 17:35 UTC on April 18, 2026, the attacker executed a sophisticated exploit by sending a malicious LayerZero packet (nonce 308). This attack leveraged the 1/1 DVN configuration, which allowed the attacker to forge verification and mint 116,500 unbacked rsETH tokens valued at $292 million on Ethereum. The funds were then deposited as collateral on major lending platforms like Aave V3, Compound V3, and Euler, enabling borrows exceeding $236 million in Wrapped Ether (WETH) and other
    Who feels it first (and how)?
    DeFi investors: Immediate losses from liquidity crunches and asset devaluations. Lending platforms: Significant drops in total value locked and operational disruptions. Developers and security teams: Increased scrutiny and pressure to enhance security measures across protocols. UAE crypto investors: Indirect effects from DeFi TVL declines and AAVE price drops, amplifying local market volatility.
    What to watch next?
    Security audits: Increased demand for comprehensive security audits across DeFi protocols will likely emerge as a response to this exploit. Market reactions: Watch for further declines in total value locked across DeFi platforms and potential shifts in user trust towards centralized exchanges. Regulatory developments: Although no governmental interventions have been noted, increased scrutiny from regulators could reshape the landscape of decentralized finance.
    12 Articles
    Crypto Briefing

    $280M KelpDAO exploit raises DeFi security concerns, impacts Solana markets

    The KelpDAO exploit has resulted in a significant loss of approximately $280 million, raising serious concerns about the security vulnerabilities within decentralized finance (DeFi) infrastructure and its potential impact on investor confidence and m...

    Bitcoinist

    What The Kelp DAO’s $292 Million Hack Means For XRP Holders Earning Yield

    A significant security breach occurred at Kelp DAO over the weekend, where an attacker exploited the LayerZero-powered bridge, resulting in the loss of approximately $292 million in tokens. This incident marks one of the largest hacks in decentralize...

    Bitcoinist

    LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit

    LayerZero has addressed the recent $290 million exploit of KelpDAO, detailing how the incident unfolded and asserting that it was not a failure of their protocol. The exploit, which drained significant funds from KelpDAO's LayerZero-powered bridge, h...

    CoinDesk

    A $300 million borrowing spike on Aave signals liquidity crunch after KelpDAO exploit

    Aave has experienced a significant liquidity crunch, marked by a $300 million spike in borrowing, following the KelpDAO exploit that drained approximately $292 million from its reserves. This incident has caused widespread instability in the stableco...

    CoinDesk

    The $13 billion DeFi wipeout in two days, and it started with KelpDAO attack

    The decentralized finance (DeFi) sector has experienced a significant downturn, with a total value locked (TVL) decline of approximately $13 billion within two days, primarily triggered by the KelpDAO exploit. This incident has led to substantial wit...

    CoinDesk

    The $292 million Kelp exploit: how it happened, and what it means for DeFi

    The Kelp exploit has resulted in a staggering loss of approximately $293 million, marking a significant breach in the decentralized finance (DeFi) sector. This incident has raised alarms about the vulnerabilities inherent in interconnected DeFi platf...

    Cointelegraph

    Kelp exploit highlights problem with non-isolated DeFi lending: Crypto execs

    The Kelp restaking platform has experienced a significant security breach, resulting in a loss of approximately $293 million due to an exploit involving rsETH. This incident has raised alarms within the decentralized finance (DeFi) sector, highlighti...

    Bitcoinist

    Kelp DAO Suffers $292 Million rsETH Exploit – Details

    Kelp DAO has experienced a significant security breach, with approximately $292 million drained from its reserves due to an exploit involving 116,500 rsETH. This incident raises serious concerns about the security of the protocol, especially followin...

    Crypto News

    Kelp attack spreads risk across DeFi, $293M lost

    The Kelp restaking platform has suffered a significant security breach, resulting in a loss of approximately $293 million due to an exploit involving rsETH. This incident has triggered disruptions across multiple decentralized finance (DeFi) protocol...

    Cointelegraph

    Kelp restaking platform exploited, $293M drained in attack

    The Kelp restaking platform has been exploited, resulting in a significant loss of approximately $293 million. This attack has triggered a

    CoinDesk

    2026's biggest crypto exploit: $292 million gets drained from Kelp DAO with wrapped ether stranded across 20 chains

    An attacker exploited Kelp DAO's LayerZero-powered bridge on Saturday, draining approximately $292 million, including 116,500 rsETH, which constitutes about 18% of the circulating supply. This incident triggered emergency freezes across several platf...

    Bitcoin.com

    ZachXBT Flags $280M+ KelpDAO Exploit Hitting Ethereum DeFi Lending Markets

    ZachXBT has flagged a significant exploit involving KelpDAO, which has reportedly led to over $280 million in losses within Ethereum's decentralized finance (DeFi) lending markets. This incident raises alarms about the security vulnerabilities presen...