KelpDAO Loses $280 Million in DeFi Wallet Drain Across Ethereum, Arbitrum

BlockchainApril 18, 2026·5 min read

A $280 million theft from KelpDAO represents one of the largest wallet compromises on record and signals intensifying attacks against institutional and whale-sized DeFi positions across multiple blockchains. For asset managers and custodians, the incident underscores the operational risk of managing large protocol exposures across fragmented chains and the persistent vulnerability of private-key infrastructure to social engineering and phishing campaigns.

  • KelpDAO lost $280 million across Ethereum and Arbitrum after attackers drained DeFi positions and consolidated 75,700 ETH into a single wallet.
  • On-chain investigator ZachXBT identified six attacker-controlled wallets funded via Tornado Cash mixer hours before the theft began on April 18.
  • The incident follows a January 2026 phishing attack that cost a single victim $284 million, signaling a sustained rise in targeted whale attacks.
  • $280M Total value drained from KelpDAO across Ethereum and Arbitrum protocols
  • 75,700 ETH Amount consolidated by attackers into single wallet, worth approximately $178 million
  • 70% Percentage of January 2026 crypto theft losses attributed to single phishing victim’s compromise

KelpDAO suffered a catastrophic breach on April 18, losing more than $280 million after attackers systematically drained positions across multiple DeFi protocols on both Ethereum and Arbitrum. On-chain investigator ZachXBT flagged the incident and identified six attacker-controlled wallets actively moving stolen funds in real time.

Within approximately one hour of the theft’s initiation, the attackers had consolidated roughly 75,700 ETH, valued at around $178 million at current market rates, into a single address. The remaining stolen value consisted of additional tokens and positions held on Arbitrum.

As of the incident’s public disclosure, no outflows from the primary consolidation wallet had been detected, suggesting the attacker may be holding or laundering the assets through privacy channels.

Tornado Cash Funding Precedes Systematic Liquidation Across Two Blockchains

Blockchain analysis reveals that the six attacker wallets received their initial funding through Tornado Cash, the privacy mixer service, hours before the theft commenced. This timing and methodology point to a coordinated, pre-planned operation rather than an opportunistic exploit.

The attacker then executed a systematic series of token approvals and swaps, first through KyberSwap and then targeting KelpDAO positions directly, before converting all holdings into raw ETH.

The operational pattern strongly suggests a private-key compromise rather than a vulnerability in any single smart contract. ZachXBT noted on Telegram: “KelpDAO appears to have had $280M+ stolen one hour ago on Ethereum and Arbitrum.

The attack addresses were funded via Tornado Cash.” The victim, likely an institutional or whale-sized holder, had accumulated significant DeFi exposure spanning both chains, and the attacker systematically liquidated those positions with precision. The rapid consolidation into a single wallet demonstrates both technical sophistication and prior reconnaissance of the victim’s on-chain holdings.

Security analysts have flagged the incident as consistent with advanced persistent targeting of high-value accounts rather than an indiscriminate protocol-wide vulnerability.

Private-Key Compromise Reflects Escalating Phishing and Social Engineering Threats

The KelpDAO incident arrives amid a documented surge in phishing and social engineering attacks specifically targeting whale-tier crypto holders. In January 2026 alone, a single phishing victim lost $284 million, which accounted for over 70 percent of the entire month’s total crypto theft losses across all attack vectors.

If confirmed at the reported figure, the KelpDAO breach would rank among the largest individual wallet compromises ever recorded on public blockchains.

The concentration of January’s losses in a single phishing incident underscores the vulnerability profile facing institutional players: one successful social engineering campaign against a trader, engineer, or key holder can dwarf the losses from technical exploits or market volatility.

For custodians and portfolio managers, the data suggests that private-key security architecture remains the critical failure point, despite advances in smart contract auditing and protocol hardening. The use of Tornado Cash to stage the attack wallets also demonstrates attacker familiarity with privacy infrastructure, indicating a degree of operational maturity beyond script-kiddie-level theft.

Industry security analysts are expected to publish deeper on-chain forensics in coming hours, potentially revealing additional details about the attacker’s identity or end-stage fund movement.

Aave Multisig Moves to Freeze Staked ETH Positions as Contagion Risk Emerges

In response to the KelpDAO drain, the Aave multisig guardian function executed a freeze on rsETH (KelpDAO’s restaked ETH token) across Aave’s lending markets.

This defensive action prevents the attacker from using stolen rsETH as collateral to borrow additional assets, but it also highlights the interconnectedness of major DeFi protocols and the speed at which risk spreads across the ecosystem once a major position is compromised.

The rsETH freeze raises a broader institutional concern: when a single large holder is drained, downstream lending and collateral markets face immediate counterparty risk. Aave’s rapid response prevented potential secondary losses, but it also required the protocol to exercise governance authority under crisis conditions.

For institutions holding liquid staking tokens or protocol-specific assets, the incident demonstrates that portfolio insurance is incomplete without accounting for operational security at the token issuer level. A stolen position is not simply a market loss; it becomes a systemic contagion point.

The freeze is temporary and contingent on further investigation and coordination with KelpDAO’s recovery efforts.

Pump.fun Instagram Compromise Compounds Ecosystem-Wide Confidence Crisis

Separately, reports emerged on April 18 that the Instagram account of Solana meme coin launchpad Pump.fun had been compromised. The platform’s team issued a public warning: “Any posts made from the official pump fun Instagram account should not be trusted.

Ignore any and all posts made by the account until we have secured the account.” Despite the breach, Pump.fun’s core infrastructure remained operational and user funds held on the platform were not affected.

While less severe than the KelpDAO private-key compromise, the Pump.fun breach reflects a secondary attack vector that targets user confidence and market sentiment. Compromised social media accounts can drive phishing campaigns, pump-and-dump schemes, or reputational damage that weakens user trust during periods of ecosystem stress.

Institutional investors monitoring emerging market infrastructure have noted the clustering of these incidents within a narrow timeframe, which some analysts attribute to coordinated campaigns or heightened attacker opportunism during market transitions.

Pump.fun did not report direct fund loss, but the incident reinforces the importance of multi-layer authentication and compromise detection at the organizational level.

Institutional investors and custody providers should expect detailed on-chain forensics from leading security firms within 48 hours, which may clarify whether the attacker is a professional theft ring, a nation-state actor, or an insider with advance knowledge of KelpDAO’s infrastructure and holdings. The key question for market participants remains whether the stolen ETH will be moved to exchange wallets for liquidation, routed through privacy protocols, or held as leverage for ransom negotiation. Additionally, the Aave multisig’s freeze sets a precedent for governance intervention during security crises; further coordination between major protocols and Ethereum validators may follow if additional large positions are threatened.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe