Kelp DAO suffers $293 million exploit attributed to Lazarus Group

Here's what it means for you.
If you’re involved in finance or blockchain, expect heightened scrutiny and potential delays in blockchain initiatives from major banks.
Why it matters
This incident underscores the vulnerabilities in decentralized finance (DeFi) and could reshape traditional finance's approach to blockchain technology.
What happened (in 30 seconds)
- Kelp DAO was exploited for $293 million on April 18, 2026, due to a vulnerability in its cross-chain bridge.
- Attackers, linked to North Korea's Lazarus Group, compromised RPC nodes and minted unbacked tokens to drain assets from lending protocols like Aave.
- Jefferies analyst Andrew Moss warned that the exploit could lead to a $9-14 billion decline in total value locked (TVL) across DeFi, prompting banks to reassess their blockchain strategies.
The context you actually need
- DeFi's rapid growth has led to increased reliance on cross-chain bridges, which can create single points of failure.
- Recent hacks, including a $285 million exploit earlier in April 2026, have raised alarms about security in the DeFi space, contributing to a total of $606 million in losses that month.
- The Kelp DAO exploit occurred amid a broader trend of traditional finance adopting blockchain for asset tokenization, following regulatory advancements like the U.S. CLARITY Act.
What's really happening
On April 18, 2026, Kelp DAO fell victim to a sophisticated attack that exploited a vulnerability in its LayerZero cross-chain bridge. Attackers compromised two remote procedure call (RPC) nodes, deploying malicious software alongside a targeted Distributed Denial of Service (DDoS) attack. This allowed them to mint 116,500 unbacked rsETH tokens, valued at $293 million, which were then used as collateral to borrow $190 million in ETH and other assets from lending protocols, including Aave.
The exploit highlights a critical flaw in Kelp's security setup, which utilized a single-verifier model despite warnings from LayerZero about the risks associated with such configurations. The attackers, attributed to North Korea's Lazarus Group, demonstrated a high level of sophistication in their approach, leveraging both technical vulnerabilities and social engineering tactics to execute the exploit.
In the aftermath, Aave responded by freezing rsETH markets and adjusting loan-to-value ratios to zero, effectively halting further losses. The Arbitrum Security Council intervened, freezing $71 million in ETH linked to the hackers. However, the broader implications of this exploit extend beyond Kelp DAO itself. Jefferies analyst Andrew Moss noted that the cascading effects of this incident could lead to a significant decline in total value locked (TVL) across DeFi, estimated between $9 billion and $14 billion. This decline may compel major banks to reassess their blockchain initiatives, particularly those focused on tokenization and asset management.
The exploit has already triggered a wave of user withdrawals from DeFi platforms, resulting in a notable drop in TVL. Aave's token value fell by 15%, while Bitcoin rebounded above $76,000, indicating a complex market reaction. Despite the chaos in DeFi, traditional markets have not yet shown signs of spillover effects, but analysts are closely monitoring the situation for potential shifts in Wall Street's approach to blockchain technology.
Who feels it first (and how)
- DeFi investors: Users may experience immediate financial losses and reduced liquidity in the market.
- Traditional banks: Financial institutions may face delays in blockchain initiatives as they reassess security protocols.
- Regulatory bodies: Increased scrutiny on DeFi platforms could lead to new regulations aimed at enhancing security and consumer protection.
What to watch next
- Security audits: Expect a surge in demand for comprehensive security audits of DeFi protocols as investors seek to mitigate risks.
- Market reactions: Monitor how major DeFi platforms adjust their security measures and whether traditional finance firms pause blockchain projects.
- Regulatory developments: Watch for potential regulatory responses aimed at addressing vulnerabilities in DeFi and enhancing consumer protections.
The Kelp DAO exploit resulted in a $293 million loss and a significant decline in DeFi TVL.
Major banks will reassess their blockchain strategies and may delay initiatives due to heightened security concerns.
The long-term impact on DeFi's growth trajectory and regulatory responses remains uncertain.
Frequently Asked Questions
- Why it matters?
- This incident underscores the vulnerabilities in decentralized finance (DeFi) and could reshape traditional finance's approach to blockchain technology.
- What happened (in 30 seconds)?
- Kelp DAO was exploited for $293 million on April 18, 2026, due to a vulnerability in its cross-chain bridge. Attackers, linked to North Korea's Lazarus Group, compromised RPC nodes and minted unbacked tokens to drain assets from lending protocols like Aave. Jefferies analyst Andrew Moss warned that the exploit could lead to a $9-14 billion decline in total value locked (TVL) across DeFi, prompting banks to reassess their blockchain strategies.
- What's really happening?
- On April 18, 2026, Kelp DAO fell victim to a sophisticated attack that exploited a vulnerability in its LayerZero cross-chain bridge. Attackers compromised two remote procedure call (RPC) nodes, deploying malicious software alongside a targeted Distributed Denial of Service (DDoS) attack. This allowed them to mint 116,500 unbacked rsETH tokens, valued at $293 million, which were then used as collateral to borrow $190 million in ETH and other assets from lending protocols, including Aave. The ex
- Who feels it first (and how)?
- DeFi investors: Users may experience immediate financial losses and reduced liquidity in the market. Traditional banks: Financial institutions may face delays in blockchain initiatives as they reassess security protocols. Regulatory bodies: Increased scrutiny on DeFi platforms could lead to new regulations aimed at enhancing security and consumer protection.
- What to watch next?
- Security audits: Expect a surge in demand for comprehensive security audits of DeFi protocols as investors seek to mitigate risks. Market reactions: Monitor how major DeFi platforms adjust their security measures and whether traditional finance firms pause blockchain projects. Regulatory developments: Watch for potential regulatory responses aimed at addressing vulnerabilities in DeFi and enhancing consumer protections.
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
Crypto's massive exploit may force big banks to rethink their blockchain plans, Jefferies warns
The Kelp DAO suffered a significant exploit, resulting in approximately $293 million being drained from its reserves due to vulnerabilities in its LayerZero-powered bridge. This incident has raised alarms regarding the security of decentralized finan...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Kelp DAO exploit fallout deepens as attacker routes $175M in ETH via privacy rails
The Kelp DAO has suffered a significant exploit, resulting in approximately $290 million drained from its reserves, with the attacker now moving $175 million in Ether through various wallet addresses to obscure the stolen funds. This breach has raise...
Bitcoin news, technical analysis, and forecasts across crypto markets.
"NewsBTC covers Bitcoin news, technical analysis, and forecasts across crypto markets and major blockchain projects."
— A47 Editor
A $292M Hack Created $200M In Bad Debt On Aave: Here Is What That Means For Users
Aave is grappling with a significant crisis following a $292 million hack that exploited a vulnerability in Kelp's bridge, leading to the creation of approximately $200 million in bad debt on its platform. The exploit allowed attackers to use stolen ...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
What The Kelp DAO’s $292 Million Hack Means For XRP Holders Earning Yield
A significant security breach occurred at Kelp DAO over the weekend, where an attacker exploited the LayerZero-powered bridge, resulting in the loss of approximately $292 million in tokens. This incident marks one of the largest hacks in decentralize...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Kelp DAO blames LayerZero defaults for $290m rsETH bridge disaster
Kelp DAO has attributed a significant security breach, resulting in a loss of approximately $290 million from its rsETH bridge, to LayerZero's default single-validator setup. This incident has sparked a blame game between Kelp DAO and LayerZero, with...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Kelp exploit highlights problem with non-isolated DeFi lending: Crypto execs
The Kelp restaking platform has experienced a significant security breach, resulting in a loss of approximately $293 million due to an exploit involving rsETH. This incident has raised alarms within the decentralized finance (DeFi) sector, highlighti...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
Kelp DAO Suffers $292 Million rsETH Exploit – Details
Kelp DAO has experienced a significant security breach, with approximately $292 million drained from its reserves due to an exploit involving 116,500 rsETH. This incident raises serious concerns about the security of the protocol, especially followin...