According to this week’s report from crypto market tracker CryptoRank, DeFi platforms suffered 121 hacks so far this year, resulting in approximately $942 million in losses.
The second quarter accounted for 85 incidents and about $775 million stolen, placing it as the most active period ever for exploits in the crypto sector.
The surge in attacks is against a backdrop of a crypto market struggle, pervaded by weakening investor confidence. Total value locked (TVL) in DeFi protocols has fallen every month this year, dropping from about $115 billion in January to $70 billion in late June.
Drift Protocol, KelpDAO Exploits Hiked Q2 Losses
Per CryptoRank’s data, Q2 2026’s 85 incidents are 49 more than the period with the second-highest frequency of exploits, which happens to be Q1 2026. However, total dollar-denominated losses were not as high as previous peaks, with the data provider reporting that two back-to-back attacks in April accounted for the majority of losses recorded in the quarter.
Drift Protocol and KelpDAO lost a combined $590 million, which is more than half of all the DeFi losses recorded in 2026. Drift Protocol disclosed that attackers had stolen about $285 million in user assets, with blockchain intelligence firm TRM Labs’s investigations linking the operation to hacking outfits connected with North Korea.
According to TRM, preparations for the attack started on-chain as early as March 11 with a 10 ETH withdrawal from Tornado Cash. The crypto tumbler transaction came after months of in-person meetings between the Pyongyang proxies and Drift employees.
“The attacker used social engineering to induce Drift Security Council multisig signers into pre-signing transactions that appeared routine but carried hidden authorizations for critical admin actions,” the firm wrote in a report published April 30.
Just over two weeks later, North Korea’s Lazarus Group exploited the liquid restaking protocol KelpDAO’s LayerZero bridge infrastructure and stole roughly $290 million worth of rsETH.
Chainalysis mentioned at the time that the attackers forged a cross-chain message on April 18 after compromising two remote procedure call nodes used by LayerZero’s Decentralized Verifier Network. At the same time, the criminals struck a third node with a distributed denial-of-service attack, making the system use compromised verifiers.
The verification process was rigged to allow for the creation of rsETH tokens on Ethereum without burning the corresponding assets on Unichain. Within days of the attack, lending protocol Aave’s TVL dropped from $26.4 billion to $14.3 billion, clocking $12 billion in withdrawn funds and a decline of about 46%.
Hacks Were One Problem; a Shrinking Market Was Another
Aave’s TVL dip wasn’t unique, with CryptoRank’s data showing the value locked in all of DeFi falling every single month in 2026, going from $115.3 billion in January to just over $70 billion in June. And while hacks were not the main reason for the decline, the firm noted that the frequency of incidents likely made users less confident, leading to a wider rotation away from the sector.
But the drop hasn’t been as bad as the one in the 2021-2022 cycle when the DeFi TVL tanked more than 70% in seven months. The current dip has been much slower, and the market has also been different structurally, CryptoQuant says, with the stablecoin supply growing to about $300 billion, real-world asset tokenization expanding, and capital dispersed across more sectors like derivatives, infrastructure, and lending, instead of being concentrated in a handful of AMMs and yield farms.
However, among the largest ecosystems by TVL, only Tron and Hyperliquid have managed to grow this year, with the former gaining 5% and the latter adding nearly 7% as it became the dominant venue for on-chain perpetuals. The rest of the top 10 chains are deeply in the red, with the worst hit being Plasma and Arbitrum, which have so far seen their TVL plunge by 74.6% and 55%, respectively.
The rsETH crisis resulted in $200 million in bad debt on Aave’s books, despite not a single line of its contracts misbehaving.
On Apr. 18, attackers that Chainalysis preliminarily linked to Lazarus compromised RPC infrastructure, forced a failover to poisoned nodes via DDoS, and injected false data into a 1-of-1 DVN configuration on KelpDAO’s rsETH bridge.
The forged message released approximately 116,500 rsETH, and Aave’s incident report confirmed that Ethereum accepted nonce 308 while the Unichain source endpoint never advanced past 307.
The attacker supplied the compromised rsETH to Aave and borrowed against it, resulting in bad debt and serving as a frame for the current state of DeFi’s security.
Exploiters extracted over $635 million across 28 incidents in April, the worst monthly total in over a year. DefiLlama puts the cumulative historical cost of hacks at $16.5 billion, with $7.7 billion specifically targeting DeFi.
The high-profile exploits on Drift and the KelpDAO bridge resulted in DeFi losing nearly $11 bilion in total value locked last month.
That contraction occurred as stablecoin rails, tokenized treasuries, and regulated settlement layers gained institutional traction in the same capital markets.
DeFi exploiters extracted $635 million across 28 incidents in April, the sector’s worst monthly loss in over a year, while cumulative historical hacks reached $16.5 billion.
How did DeFi end up here?
Mitchell Amador, CEO of Immunefi, told CryptoSlate that DeFi has historically rewarded growth, integrations, liquidity, and speed over security maturity.
A protocol that adds a new asset, bridge, oracle, adapter, or external dependency gains immediate utility. The risk that integration carries produces no visible price signal until an exploit materializes, because the absence of an incident is invisible while it holds.
That asymmetry kept audit cycles and isolation practices secondary to shipping velocity for years, until April concentrated the consequences into a single month.
Amador said the most overlooked practices were multisig hygiene and management, supply chain hardening, real-time monitoring, and emergency response procedures.
Too many teams treated multisig as a security solution in itself, when its actual strength depends on signer count, the independence of those signers, their operational setup, and the processes around transaction review.
A low-threshold multisig, weak signer security, or a poorly monitored bridge or oracle can become a systemic exposure because DeFi protocols are composable by default. In this landscape, risk travels through integrations as efficiently as liquidity does.
While that culture was forming inside DeFi, a different model was being built in parallel.
“The gap in output per person tells you what happens when you strip away everything that isn’t the core financial function. The teams that win this round will be the ones built on compliance and security from day one, ready to ship faster than a bank can call a meeting about it.”
DeFi built composable rails for over half a decade before Wall Street recognized them as the actual infrastructure layer of the next financial system.
The cost of that early market position was a security culture calibrated for speed over operational discipline.
Kasper Pawlowski, CTO of Euler Finance, names the governance dimension of the same failure in his post-incident analysis.
He said:
“DeFi treats risk assessment as a one-time onboarding decision, when in reality risk is dynamic.”
The 1-of-1 DVN configuration that enabled the KelpDAO exploit existed in production for years. Kelp says it was the default LayerZero shipped and reviewed across multiple integration meetings, while LayerZero says Kelp downgraded to it.
Whichever account is accurate, the configuration persisted unflagged through every integration with every downstream protocol. LayerZero has since banned the configuration on a protocol-wide basis, acknowledging that allowing its DVN to act as the sole verifier for high-value transactions was a mistake.
Stage
What happened
Why it mattered
RPC infrastructure compromised
Attackers compromised RPC infrastructure tied to the rsETH bridge setup
The attack began outside the core smart contracts, showing how off-chain infrastructure can become the entry point
DDoS forced failover
Traffic was pushed onto poisoned nodes through a forced failover
That let attackers control the data environment seen by the bridge verifier
False data injected into 1-of-1 DVN
Poisoned nodes fed false data into a single-verifier DVN configuration
A 1-of-1 verifier setup meant there was no independent check to stop the forged message
Forged bridge message accepted
The forged message released about 116,500 rsETH
Fake collateral was effectively minted into circulation
Fake rsETH supplied to Aave
The attacker deposited compromised rsETH into Aave as collateral
Aave treated the asset as valid and allowed borrowing against it
Borrowing created bad debt
The attacker borrowed other assets and left Aave with roughly $200 million in bad debt
Losses from a bridge failure migrated into a lending market and were socialized across the pool
The more consequential point is that a critical bridge-security parameter was normalized across the entire dependency chain until a $292 million exploit surfaced it.
Pawlowski argued:
“The operational machinery DeFi has built — DAO governance, external risk service providers, and monthly review cycles — doesn’t move at the speed the underlying risk surface does. In many cases, the people doing the reviewing aren’t structurally independent of the assets they’re reviewing.”
That structural conflict produced the specific governance failure Pawlowski dissected. Aave’s 25,000 ETH treasury recovery proposal was authored by TokenLogic, a paid Aave service provider that publicly lists Kelp as a client and operates an Aave delegate platform.
For reference, TokenLogic is the same firm voting on its own proposals. On the same day Aave expanded rsETH to a 93% loan-to-value ratio in eMode, SparkLend deprecated the asset entirely, bundling the move with routine cleanup of underused positions.
Three months later, that routine pruning was the only separation between Spark’s depositors and the bad debt Aave now carries.
One protocol’s independent risk judgment outperformed another’s full-stack risk advisory apparatus. DeFi’s review machinery generated worse outcomes than a single asset manager doing portfolio hygiene.
What “here” means
Before the exploit, Aave was the largest DeFi protocol by total value locked, with over $26 billion in deposits.
Pawlowski noted:
“Aave was the gold standard. If Aave can carry $200 million-plus in bad debt from a bridge exploit on a different protocol, the market has to recalibrate what ‘safe’ actually means in DeFi lending.”
The pooled lending model is only as strong as its weakest accepted collateral, and when that collateral breaks, the entire shared pool absorbs the damage. The exposure reaches every depositor in the broader market, extending well past the vault that held the position.
Protocol
Decision on rsETH
Risk posture
Outcome
Aave
Expanded rsETH to a 93% loan-to-value ratio in eMode
More aggressive onboarding and collateral treatment
Ended up exposed to the compromised asset and now carries bad debt
SparkLend
Deprecated rsETH as part of routine cleanup of underused positions
More conservative portfolio and listing hygiene
Avoided the exposure that later hit Aave
Pawlowski pointed out that the structural reality had been “muted by years of ‘battle-tested’ and ‘blue-chip’ marketing.”
Amador broadened the exposure map beyond the mechanics of KelpDAO. The attack surface in DeFi now covers governance, signers, privileged roles, integrations, bridges, oracles, custody arrangements, and every external system a protocol depends on.
The most dangerous operational assumption a team can hold is that audited smart contracts equal a safe protocol. Immunefi’s own research shows that DeFi losses declined by as much as 80% over the last several years, because the sector hardened its code and attackers adapted.
Amador added that they now study the entire risk chain for the weakest points, and those points are now off-chain, governance-adjacent, or buried in dependency stacks that no single audit covers.
For institutions, April forced a specific reset. Amador described the checklist now: how admin keys are managed, who can pause markets, what dependencies exist, what the incident response process looks like, and how quickly a threat can be contained.
Pawlowski made the same point from the capital side, saying institutions will continue to enter on-chain credit because the demand for tokenized markets, transparent settlement, and programmable financial infrastructure is real.
However, the institutional investors will move toward isolated markets, permissioned or curated vaults, stricter asset onboarding, better insurance, continuous monitoring, and formalized emergency controls.
DeFi exploiters extracted $635 million across 28 incidents in April, the sector’s worst monthly loss in over a year, while cumulative historical hacks reached $16.5 billion.
Aave Horizon, a permissioned market for tokenized securities and RWAs launched in August 2025, has grown to more than $440 million in deposits.
Morpho’s vault ecosystem added ARCHITECT, the first FINMA-licensed investment manager to curate vaults at scale, and Flowdesk launched an institutional AUSD vault in March 2026, using tokenized equities as collateral.
EY-Parthenon and Coinbase’s 2026 survey found 73% of institutional respondents plan to increase digital asset allocations this year, but 81% prefer registered vehicles. Capital is moving on-chain through curated, governed, and compliance-aware structures.
The regulated alternative is accelerating on the other side of that same preference.
The GENIUS Act created the first federal framework for US stablecoins, with mandatory 100% reserve backing, no rehypothecation, and custody standards that Nadareski said “read like something a compliance desk could approve.”
A Goldman Sachs survey found 35% of institutional investors named regulatory uncertainty their biggest blocker, and 71% said they would increase exposure once clarity arrived.
Nadareski said, “The floor is in place, the capital is waiting.” The CLARITY Act, which would define jurisdictional and custodian standards for digital assets, including tokenized securities, awaits consideration by the Senate Banking Committee as of May 14.
When that passes, Nadareski argued that “the last item on most institutional checklists gets checked off. The waiting ends.” DeFi is competing for institutional capital against a nearly complete regulatory framework.
How DeFi resurges
Pawlowski named the full list of DeFi recovery tools: governance combined with proper market isolation, automated and AI-assisted risk monitoring, selective timelocks on parameters that warrant them, circuit breakers, KYC when required by regulation, application-specific sequencing, and policy-aware block builders.
He added:
“What’s been missing is the willingness to use them, because every one [of the tools] involves a tradeoff against the maximalist version of decentralization the industry has marketed itself on.”
Abandoning that marketing position is the starting point, but it’s not easy.
Pawlowski noted that “the crypto industry has spent years pretending it can have everything”, such as full decentralization, censorship resistance, institutional-grade safety, and retail accessibility, without tradeoffs.
It was “that fantasy that produced the conditions for these exploits.” A regulated institutional credit facility on-chain is a different product from a permissionless retail lending market, and governing both under the same orthodoxy created the conditions that let aggressive rsETH listings clear governance while structural bridge-security parameters sat unflagged for years.
Pawlowski believes the structural fix requires ending “the conflicts that let aggressive listings get waved through low-turnout governance votes by service providers with commercial relationships on both sides of the trade.”
SparkLend’s independent pruning, versus Aave’s eMode expansion on the same day, is proof that different risk philosophies yield different outcomes.
DeFi needs to institutionalize that distinction, build governance structures around it, and make the tradeoffs explicit to every user and institution evaluating the protocol.
Amador’s operational prescription attacks the same problem from the execution layer.
DeFi must professionalize security in the same way it professionalized liquidity incentives via continuous audits, live bug bounty programs, formal verification where appropriate, independent security councils, stronger multisig thresholds, hardware-backed key management, real-time monitoring, public incident response playbooks, and mandatory risk reviews for every major integration.
Circuit breakers and isolation mechanisms should be built so that losses from a compromised asset, adapter, or dependency stay bounded within the affected market.
The benchmark for evaluating protocols should expand to cover security posture alongside yield and total value locked: who audited it, what the active bounty size is, how admin keys are managed, what dependencies exist, what the emergency procedure covers, and how quickly a threat can be contained.
Users and institutions should be able to compare protocols on those dimensions the way they compare APR.
Capability
Why it matters
What it looks like in practice
Market isolation
Prevents one compromised asset or dependency from contaminating a shared pool
Keeps risk assessment dynamic rather than one-time
Mandatory reviews for major integrations, recurring audits, formal verification where appropriate
Incident response readiness
Improves containment and recovery when something breaks
Public response playbooks, recovery guardians, predefined recovery procedures
Security transparency
Lets users and institutions compare protocols beyond yield
Clear disclosure of audits, bounty size, dependencies, admin controls, and response plans
A reform is already underway, as KelpDAO has begun migrating rsETH to Chainlink CCIP, LayerZero has banned 1-of-1 verifier configurations protocol-wide, and Aave Proposal 477 authorized liquidation of attacker positions, with recovered assets routed to a Recovery Guardian multisig.
Phase II of that proposal covers burning excess rsETH on Arbitrum, restoring bridge backing, reopening withdrawals, and compensating affected users.
Arbitrum’s Security Council separately froze 30,766 ETH tied to the attacker’s downstream funds.
That recovery required emergency councils, DAO votes, multisigs, and court proceedings, comprising a crisis-management stack drawn from the institutional finance playbook, deployed within a system that describes itself as permissionless.
DeFi reaches for those tools when losses get large enough, and protocols can embed them in advance or reconstruct them while a crisis unfolds.
DeFi’s case for composability
Nadareski identified the specific prize at stake for institutions choosing between DeFi and regulated alternatives.
Compliance officers want circuit breakers, time-locks, and custody standards that match their existing playbooks, and Wall Street has been building that wrapper for years.
Nadareski said:
“The banks that move fastest will be the ones that stop trying to build everything in-house. Spinning up on-chain settlement with legacy teams puts you at 2028 if everything goes right. The play that ships this year is pairing established distribution and customer relationships with teams who already have the rails built.”
Composability is DeFi’s strongest argument for keeping the rails it built. A single protocol that executes a trade, manages collateral, routes liquidity, and automatically settles a transaction within seconds represents a capability that traditional finance can only replicate by rebuilding from the ground up.
Composability works as an institutional argument only if failures stay local. Once a bridge verifier, a governance vote, or a compromised oracle can transmit losses across shared liquidity pools at scale, composability operates as contagion infrastructure.
Amador noted:
“Trust the code is not enough when protocols depend on bridges, multisigs, governance processes, or external assets. The new standard has to be: assume every layer can fail, and design systems so one failure does not cascade into the entire market.”
Pawlowski framed the necessary changes as “growing up,” describing a sector that must accept and publish explicit tradeoffs, build genuinely independent governance structures, and make security a product feature that users and institutions can evaluate and compare.
DeFi built the composable infrastructure that tokenized markets are now adopting. Stablecoin rails, lending primitives, and liquidity mechanisms that originated inside permissionless DeFi are being packaged into products that Wall Street is shipping under regulatory cover.
If DeFi builds the operational maturity to match its technical architecture, composability remains the one capability beyond the reach of regulated wrappers. If DeFi fails to build that maturity, Wall Street captures the stablecoin and tokenization layer and, with it, the argument that open composable finance lacked the operational discipline serious capital requires.
Arbitrum’s Security Council Seizes $71M in Stolen ETH After KelpDAO Bridge Hack
BREAKING · APRIL 21, 2026 · ARBITRUM · DEFI ANALYSIS
Arbitrum’s Security Council Seizes $71M in Stolen ETH After KelpDAO Bridge Hack
Arbitrum’s Security Council just immobilized $71 million in stolen ETH. One emergency vote.
Nine signatures. And a question that won’t go away: can a “decentralized” network
really freeze your funds?
ETH Frozen30,766 ETH ≈ $71M
Original Exploit$292M rsETH
Council Vote9 of 12 in favor
Suspected ActorLazarus Group (DPRK)
$292MTotal Exploit Value
$71METH Frozen by Arbitrum
18%rsETH Supply Drained
$230MPotential Aave Bad Debt
§ 01 — The Attack
How 116,500 rsETH Materialized Out of Thin Air
On Saturday, April 18, 2026, at precisely 17:35 UTC, someone
did something extraordinary: they minted 116,500 rsETH tokens on Ethereum mainnet
with zero legitimate backing behind them. Worth roughly $292 million
at the time, this wasn’t a flash loan attack or a smart contract reentrancy bug.
The contracts ran exactly as written. The verification layer was the weapon.
KelpDAO is a liquid restaking protocol built on EigenLayer. Users deposit ETH,
which earns compounding yield across EigenLayer’s Actively Validated Services,
and receive rsETH — a tradeable liquid restaking token representing
their position. To enable rsETH to move across the multi-chain ecosystem, KelpDAO
deployed a LayerZero-based bridge architecture using the OFT
(Omnichain Fungible Token) standard. As of the exploit, that bridge held the
backing reserve for rsETH deployed across more than 20 networks — Arbitrum, Base,
Linea, Blast, Mantle, Scroll, and more. The protocol had roughly $1.07 billion
in total value locked, making it the second-largest participant in EigenLayer’s
ecosystem. This was the reserve that was drained.
// Forged origin packet → EID 30320 (Unichain)
→ 116,500 rsETH released from escrow
→ Single Transfer · One OFTReceived · One PacketDelivered
→ ~$292,000,000 exited the protocol
The Technical Root Cause: A 1-of-1 DVN
LayerZero’s security model is built on Decentralized Verifier Networks
(DVNs) — independent entities that verify and attest to the authenticity
of cross-chain messages. When a message travels from Chain A to Chain B, one or
more DVNs must observe the packet on the source chain and deliver a signed
attestation to the destination. The critical configuration choice is how many
DVNs must agree.
KelpDAO’s rsETH bridge was configured with a 1-of-1 DVN setup —
LayerZero Labs itself as the sole verifier. A single signature was all that stood
between the bridge’s escrow and the open internet. The attackers, preliminarily
attributed to North Korea’s Lazarus Group (TraderTraitor unit),
exploited this exactly.
April 18 · 10:20 AM PT
RPC Node Compromise Begins
Attackers compromise two of LayerZero’s downstream RPC nodes, swapping out
op-geth binaries with malicious versions engineered to selectively lie to the DVN
while reporting accurate data to all other querying IP addresses.
April 18 · ~11:30 AM PT
DDoS Triggers Failover
Attackers DDoS the uncompromised RPC nodes, forcing LayerZero’s DVN to failover
to the poisoned endpoints. The malicious nodes confirm fraudulent cross-chain
transactions that never occurred on the source chain.
April 18 · 17:35 UTC
The Drain — 116,500 rsETH Released
A forged LayerZero packet claiming origin from KelpDAO’s Unichain deployment
passes the single compromised DVN. The OFT Adapter releases 116,500 rsETH
from escrow to the attacker’s address. ~$292M exits in a single transaction.
April 18 · 18:21 UTC
KelpDAO Emergency Pause (46 Minutes Later)
Kelp’s emergency multisig freezes core contracts. Two subsequent follow-up
attacks at 18:26 and 18:28 UTC — each attempting another 40,000 rsETH (~$100M)
— both revert. The pause held.
April 18–19
DeFi Contagion Spreads
Attackers weaponize stolen rsETH as Aave v3 collateral, borrowing $196M in WETH.
Aave WETH markets hit 100% utilization. Aave, SparkLend, and Fluid freeze rsETH
markets. $6.6B in TVL collapses within 48 hours across affected protocols.
§
§ 02 — The Intervention
Arbitrum’s Security Council Acts: A Race Against the Bridge
As stolen funds began moving through the ecosystem, blockchain security firm
PeckShield flagged a critical development: the exploiter had
already initiated a native bridge withdrawal from Arbitrum back to Ethereum
mainnet. The clock was ticking. If the 30,766 ETH that had been consolidated
on Arbitrum One completed the withdrawal, it would enter Ethereum’s base layer —
far harder to intercept.
The Arbitrum Security Council — a 12-member body elected by
the Arbitrum DAO through semi-annual elections — convened an emergency session.
According to council member Griff Green, the deliberation involved
“countless hours of debates, technical, practical, ethical and political.”
Nine of the twelve members voted to act. The council coordinated with law enforcement,
who provided input on the exploiter’s identity. Security researchers later linked
the operation to North Korea’s Lazarus Group.
“The Security Council identified and executed a technical approach to move
funds to safety without affecting any other chain state or Arbitrum users.”
— Arbitrum Security Council · April 21, 2026
Using the 0x0000000000000000000000000000000000000DA0 precompile
— a standard native ETH transfer mechanism — the council moved 30,766 ETH
to a protocol-controlled intermediary address. The freeze was confirmed by
Lookonchain approximately 20 minutes after execution. The
funds were intercepted before the bridge withdrawal completed.
Represents ~24% of the total $292M stolen PARTIAL RECOVERY
Remaining ~$220M moved via other chains UNRECOVERED
Lazarus Group suspected to be routing remainder LAUNDERING
For observers watching the situation unfold in real time, the move carried a weight
that went beyond the mechanics of a single freeze. Dylan Dewdney, Founder of Kuvi AI,
was among those who felt the historical echo immediately.
“It’s a fascinating moment for crypto governance — reminds me actually of the same
gravitas as TheDAO, in a way. On one hand, decentralization purists will hate it.
On the other, a DAO effectively looked at a state-sponsored hacking group and said:
not this time. Arbitrum just demonstrated that onchain systems can defend themselves
in real time. In a strange way, they out-coordinated one of the most sophisticated
adversaries in the world. Legitimately onchain gangster moves.”
— Dylan Dewdney, Founder, Kuvi AI
§
§ 03 — The Blame Game
LayerZero vs. KelpDAO: Who Owns a $292M Default?
Even as funds were being frozen, a parallel battle erupted between the two parties
at the center of the exploit. LayerZero moved first with a post-mortem attributing
responsibility squarely to KelpDAO’s configuration choices. Kelp fired back with
documentation. The dispute cuts to the heart of modular DeFi architecture.
LayerZero’s Position
LayerZero stated that KelpDAO “chose to utilize a 1/1 DVN configuration”
despite the protocol’s consistent recommendation of multi-DVN redundancy.
The firm argued that a properly hardened setup would have required consensus
across multiple independent verifiers, making the attack ineffective even with
a single node compromised. LayerZero announced it would stop signing
messages for any application using a single-validator setup going forward,
forcing a broad migration across its ecosystem.
KelpDAO’s Counter
Kelp pushed back hard. The team argued the 1-of-1 DVN was not a rogue customization
but LayerZero’s own documented default. The protocol’s
V2 OApp Quickstart — including the sample layerzero.config.ts — wires
every pathway with one required DVN and no optional DVNs. Kelp added that approximately
40% of protocols currently on LayerZero use the same configuration,
and that in the direct communications channel with LayerZero open since July 2024,
there was no specific recommendation to change the rsETH DVN setup.
@cryptogoblin · April 19, 2026
“The KelpDAO exploit (~$290M) is NOT a LayerZero protocol bug. It’s a configuration
issue and a case study every project with a cross-chain token needs to look at today.
The smart contracts weren’t broken. The verification layer was.”
@FishyCatfish · April 19, 2026
“There is no security floor. A configuration can be a 1/1 DVN and the DVN you chose
can be a single node ran by a single entity. This is a design flaw.”
Independent analysis from Blockaid confirmed: “The KelpDAO exploit will be studied
as the definitive case study in bridge DVN configuration risk. It did not require a
zero-day. It exploited a weak governance policy and limited controls.” Chainalysis
put it more bluntly: the attack proves that detecting malicious code isn’t
enough — protocols must detect when a system enters an impossible state.
§
§ 04 — DeFi Implications
The Contagion Map: From rsETH to Aave to the Whole Ecosystem
The KelpDAO exploit did not stay contained. Within 46 minutes of the drain, the
attackers began weaponizing the stolen rsETH across DeFi’s interconnected lending
infrastructure. The mechanics were straightforward and devastating.
Attackers deposited the minted rsETH on Aave v3 as collateral and
borrowed $196 million in WETH against it. Aave’s WETH market hit
100% utilization, rendering deposits inaccessible
and triggering a $5.4 billion liquidity withdrawal cascade. Total DeFi TVL collapsed
by $6.6 billion within 48 hours. Aave, SparkLend, and Fluid all froze
their rsETH markets. Lido disclosed approximately $21.6 million in rsETH exposure
through its EarnETH product and signaled it may deploy a $3 million loss buffer.
Scenario A: Losses socialized across all rsETH holders across chains
$123.7M bad debt · ~15% depeg
Scenario B: Losses isolated to L2 markets (Arbitrum, Mantle)
Up to $230.1M impact
Aave treasury backstop available $181M treasury
Umbrella model available in certain cases Active
April 2026 has become the worst month for crypto hacks since February 2025,
with over $606 million lost in just 18 days.
The KelpDAO incident came on the heels of the Drift Protocol breach
($285M, April 1) — also linked to Lazarus Group — suggesting a sustained,
coordinated campaign targeting DeFi infrastructure rather than isolated opportunistic
attacks.
The structural lesson is uncomfortable: liquid restaking tokens (LRTs)
as collateral on money markets create systemic amplification. When an
LRT loses peg or backing, lending protocols don’t just feel the impact of the
token — they absorb the entire downstream leverage built atop it. This is the
second time in 2026 that an LRT collateral accepted on Aave has produced a
nine-figure incident downstream of a non-Aave failure.
§
§ 05 — The Core Tension
The Decentralization Paradox: Safety Valve or Fatal Contradiction?
Arbitrum’s intervention was precise, effective, and — for many in the crypto
community — deeply troubling. In a single emergency session, a 12-person council
immobilized 30,766 ETH that an external party held in their address.
The funds were moved without a DAO vote, without the standard governance delay,
and without consulting the broader community before execution. The legality, the
ethics, and the precedent are all contested.
“A 12-person committee — elected by ARB token holders, sure — just demonstrated
it can immobilize any funds on the network given sufficient justification. For a
technology built on the promise of permissionless transactions, that’s either a
necessary safety valve or a fundamental contradiction.”
— Blockchain.news analysis · April 21, 2026
The Arbitrum Security Council is defined in the Constitution of the
Arbitrum DAO as a 12-member body divided into two cohorts, with members
elected in semi-annual elections by ARB token holders. The council is bound by
the Constitution to use its emergency powers only when necessary for
declared security emergencies, and must issue a transparency report when those
powers are invoked. The frozen ETH can only move through further governance action —
ARB holders will ultimately vote on its fate.
The Community Splits
For the Freeze
$71M recovered, likely from state-sponsored thieves
Zero impact on legitimate users or applications
Law enforcement coordination adds legitimacy
Funds remain under governance — not taken
DPRK laundering would have made recovery impossible
Security Council acted within its constitutional mandate
Against the Freeze
Permissionless transactions is the core value proposition
Council can theoretically freeze any funds on the network
Sets precedent for future, potentially non-consensual freezes
“Decentralized” becomes a marketing term, not a guarantee
Who decides what justification is “sufficient”?
Ethereum community has concerns about L2 centralization
@Leonidas (DOG creator) · April 21, 2026
“Decentralized has become a marketing term. Only Bitcoin is actually decentralized.”
@baeyeee · April 21, 2026
“WLFI is accused of wrongfully freezing user assets, while ARB froze stolen funds
linked to DPRK hackers. One is ethically accepted, the other is criticized — but both
prove the same point. When it matters most, governance overrides decentralization.”
@JoelKatz (Ripple CTO David Schwartz) · April 21, 2026
“They can make the chain claim that they did whatever they want to all of the funds
on the chain. But they cannot compel anyone to listen to those claims. Everyone else
can make different claims and choose which set of claims to honor.”
The Stage 2 Problem
The Arbitrum DAO’s own governance documentation asks the question directly:
“Can the governance process be further decentralized? How and when can the
Security Council’s power be further minimized, or eliminated entirely?”
These don’t have easy answers. Arbitrum achieved Stage 1 decentralization
with permissionless fraud proofs via the BoLD upgrade. But Stage 2
— which would limit the Security Council to adjudicating only demonstrable bugs —
remains a future aspiration, not a current reality.
The irony is sharp: the same emergency power that just recovered $71M in stolen funds
is precisely the mechanism that prevents Arbitrum from claiming Stage 2 decentralization.
Security and trustlessness are in direct tension, and today’s events demonstrated
that tension is not theoretical.
§
§ 06 — What Comes Next
Open Questions & The Road Forward
As of April 21, 2026, the 30,766 ETH remain locked in the protocol-controlled
address at 0x000...0DA0. No timeline has been
set for final disposition. The ARB community will vote on what happens to the funds
— options range from returning them to affected KelpDAO users to holding them pending
law enforcement proceedings. KelpDAO’s rsETH contracts remain paused. Founders
Amitej G and Dheeraj B have not announced a recovery timeline.
Open Questions as of Publication
How will ARB governance vote to allocate the frozen $71M? PENDING VOTE
Will other chains with similar emergency powers freeze their portions? UNCERTAIN
Who bears legal liability — KelpDAO, LayerZero, or both? DISPUTED
Will Aave deploy its Umbrella backstop for rsETH bad debt? MONITORING
Will LayerZero’s forced DVN migration affect other protocols? IN PROGRESS
Can the remaining $220M be traced before laundering completes? UNLIKELY
The KelpDAO exploit has accelerated three structural conversations that DeFi has
been deferring: bridge configuration standards (who sets them, who
enforces them, and who is liable when defaults cause catastrophic losses);
LRT collateral risk in money markets (the second $100M+ incident
in 2026 with restaked ETH tokens as the vector); and Layer 2 emergency
powers (the legitimate tension between user protection and permissionless
guarantees).
Chainalysis’s recommendation cuts through the noise: protocols must build systems
capable of detecting when they have entered an “impossible state” —
where issued tokens exceed locked collateral. For a cross-chain bridge, that means
real-time consistency monitoring across every deployed chain. For DeFi as a whole,
it means acknowledging that the “code is law” principle has never been fully true —
and deciding what replaces it.
“The Lazarus Group, if indeed responsible, has already moved the remaining $220 million
through various chains. Arbitrum caught what it could. The rest is likely gone.”
This week the crypto market got hit from every direction at once and held.
The Strait of Hormuz, through which roughly 20% of the world’s oil flows, flickered open and closed like a light switch over the weekend. Iran opened it Friday, Trump said the blockade stays, Iran closed it Saturday and ships came under fire. Every headline moved Bitcoin. It opened Monday down 2.5%, bounced back toward $75,000 by mid-morning as institutional buyers stepped in, and that has been the pattern all month: macro shock, dip, institutional buy. BlackRock’s IBIT alone pulled $284M in a single day on April 17. The floor is real. But BTC has failed six times to hold above $76K and the Iran ceasefire clock is still ticking. That weekly close above $76K is the signal I’m watching.
On the DeFi side, KelpDAO got exploited on Tuesday. Attackers found a flaw in the way it verified prices before processing large withdrawals and drained $293 million in 46 minutes. The ripple effect hit Aave, essentially a DeFi lending bank, which was left with $196 million in loans it may not fully recover. If you hold, lend, or earn yield on any cross-chain protocol, the full breakdown is worth reading.
Vercel confirmed a breach on April 19. It’s the platform that hosts the frontend of a huge slice of the Web3 ecosystem, the actual websites you interact with when you use a dApp. Compromised via a supply-chain attack through a third-party AI tool. If you connected a wallet to any Web3 dApp this past week, revoke any approvals you don’t recognize. Full CCS breakdown here.
For all the noise, the market didn’t break. Strategy bought 34,164 BTC for $2.55 billion this week. BitMine bought 101,627 ETH for $235 million. Institutions aren’t waiting for the all-clear signal. They’re buying the chaos.
XYO just went 2-5x faster and most people haven’t noticed yet.
Throughput jump. Dual DataLake SDK. Validator stability. All shipped at once.
Arie Trouw, Co-Founder, CEO, and CTO of XYO, breaks down exactly what changed, what was causing the bottleneck before, and why verifiable data provenance is quietly becoming one of the most important infrastructure layers as AI moves into the physical world.
BTC is still trading below its 100-day and 200-day moving averages and has failed six times to hold above $76K. Total spot ETF inflows now exceed $56 billion — that’s what keeps putting a floor under every dip.
Cautiously Bullish
The structure holds as long as $75K holds. A weekly close above $76K opens the path to $85K–$90K. A breakdown here puts $70K–$72K back in play. The macro overhang from Iran is the single biggest variable on the board right now.
What I’m watching: A confirmed daily close above $76,500 with above-average volume. Without it, every rally is a wick until proven otherwise.
ETH opened down 3.7% on the week and is in recovery mode. Bitcoin is leading and ETH is following, which is the healthy version of this setup. The Vercel breach and KelpDAO hack are headwinds for sentiment, not for the price structure itself.
Bullish — Patient
The next level to watch is $2,701, which is the major resistance before $3,519 comes back into view. ETH outperforming BTC on a percentage basis is the signal I want to see before getting more aggressive.
Vercel confirmed a breach via supply-chain attack through a third-party AI tool, exposing API keys and tokens across Web3 frontends. Solana DEX Orca rotated all credentials immediately. If you connected a wallet to any dApp this week, revoke approvals you don’t recognize. Full CCS breakdown
X’s cashtag trading pilot for stocks and crypto generated an estimated $1 billion in volume in its first week
$400 million in crypto shorts were liquidated in a single 4-hour window during the Hormuz chaos
Michael Saylor says it is “impossible to blockade Bitcoin”
$RAVE collapsed 98% in two days, erasing $6.7 billion in market cap following alleged insider manipulation
India is settling Iranian oil payments in Chinese yuan, a notable de-dollarization signal
Qastle Wallet Premium subscribers can claim a free Bitcoin 2026 Pro Pass worth $1,299. Bitcoin 2026 is April 27–29 at The Venetian, Las Vegas. Claim here
Final Word
The ceasefire between the US and Iran expires this week. That single variable has more power over Bitcoin’s price right now than any on-chain metric. If talks break down, expect another dip and another institutional buy. If a deal gets done, $76K becomes the story fast.
Watch the daily close. That’s where this week gets decided.
Ashton Addison
CEO, Crypto Coin Show
What’s moving your thinking more right now — the Iran ceasefire or the DeFi security story?
KelpDAO’s $293M Bridge Hack Left Aave Holding the Bag
How attackers forged a LayerZero message to drain KelpDAO’s rsETH bridge in 46 minutes, deposited unbacked tokens into Aave as collateral, borrowed $293M in real WETH — and left Aave with $196M in bad debt, a $13B TVL wipeout, and a governance crisis it is still fighting through today.
By Ashton Addison, Editor in Chief · Crypto Coin ShowApril 18–19, 2026Ethereum · Arbitrum · 20+ Chains10 min read
$293MTotal drained
46Minutes to drain
116,500rsETH stolen
$196MAave bad debt
$6.6BAave TVL drop
#1Largest hack of 2026
On the afternoon of Saturday, April 18, 2026, a single wallet — funded through Tornado Cash to obscure its origins — quietly positioned itself at the threshold of Kelp DAO’s cross-chain bridge. What followed in the next 46 minutes rewrote the record books for DeFi exploits, drained nearly a fifth of an entire liquid restaking token’s circulating supply, and left the largest lending protocol in decentralized finance grappling with close to $200 million in irrecoverable bad debt.
The attack on Kelp DAO is not simply the year’s biggest hack by dollar value. It is a masterclass in how interconnected DeFi infrastructure transforms a single vulnerability into a multi-protocol catastrophe — and a sobering reminder that the composability that makes DeFi powerful is also what makes it catastrophically fragile.
“The assumption underlying all of that was that the token would remain fully backed. When that assumption collapsed on Saturday afternoon, there was no circuit breaker, no committee vote, and no grace period.”
Understanding the Target: Kelp DAO and rsETH
To understand what happened, it helps to understand what Kelp DAO actually is. Kelp is a liquid restaking protocol operating under the KernelDAO umbrella. Users deposit established, already-staked Ether derivatives — tokens like stETH or cbETH — into Kelp’s adapter contracts. In return, they receive rsETH, a “receipt” token that earns staking and restaking yield through EigenLayer while remaining liquid and tradeable.
That liquidity is the key. Because rsETH represents real, yield-bearing ETH, it was accepted as collateral by nearly every major DeFi lending protocol, including Aave, SparkLend, Compound, and Euler. Billions of dollars in DeFi value rested on the implicit assumption that rsETH was, and would remain, fully backed by real assets.
To operate across Ethereum’s ever-expanding ecosystem of Layer 2 networks, Kelp relied on a LayerZero-powered Omnichain Fungible Token bridge — a cross-chain messaging system designed to confirm and relay valid transfer instructions between networks. This bridge held reserves backing rsETH across more than 20 separate blockchain networks. It was the protocol’s connective tissue. It was also its most exposed attack surface.
The Attack: A Forged Message, a Minted Fortune
Phase I — Spoofing the Bridge
Blockchain investigators, including the on-chain sleuth ZachXBT who first publicly flagged the outflow at approximately 14:52 New York time, quickly established the mechanics. The attacker did not steal private keys. They did not drain a smart contract through a reentrancy flaw. Instead, they exploited a critical vulnerability in rsETH’s bridge minting logic — specifically in the LayerZero Omnichain Fungible Token contract — by feeding the bridge a forged cross-chain instruction.
The message appeared to the bridge as a valid, legitimate transfer request arriving from another chain. The bridge’s validation layer — the system designed to confirm that a matching inbound transfer existed to anchor any mint — was fooled. It released 116,500 rsETH, worth approximately $292–$294 million at prevailing prices, to an address controlled by the attacker. No corresponding collateral existed. The tokens were, in effect, printed from nothing.
Stolen rsETH deposited into Aave V3 and V4 as collateral. Attacker begins borrowing Wrapped ETH (WETH) against the unbacked tokens, building debt positions across Aave, Compound V3, and Euler.
~18:05 UTC — Consolidation
Attacker consolidates approximately 74,000 ETH post-exploit, having extracted around 106,467 WETH (~$250M) by selling rsETH and using it as collateral to borrow.
18:21 UTC — Emergency Pause
Kelp DAO activates “pauseAll” function. rsETH deposits, withdrawals, and token movements frozen across mainnet and several L2 networks. The bulk of funds had already been extracted.
~18:30 UTC — Protocol Freezes Begin
Aave freezes rsETH markets on V3 and V4. SparkLend and Fluid follow. Lido Finance pauses earnETH deposits. Ethena temporarily pauses its LayerZero OFT bridges as a precaution.
20:10 UTC — Kelp Acknowledges
Kelp DAO posts its first public statement on X — nearly three hours after the drain — confirming “suspicious cross-chain activity” and coordination with LayerZero, Unichain, auditors, and security experts.
Phase II — Weaponizing DeFi’s Composability
The second phase of the attack was arguably more damaging than the first. The stolen rsETH did not simply sit idle in the attacker’s wallet. Having minted 116,500 tokens backed by nothing, the attacker turned immediately to DeFi’s lending markets — the very infrastructure that had accepted rsETH as a trusted collateral asset.
The attacker deposited the drained rsETH into Aave V3 as collateral and borrowed substantial volumes of Wrapped Ether against it. The same playbook was executed across Compound V3 and Euler. By the time Kelp’s emergency pause function fired — 46 minutes after the first successful drain — the attacker had already built more than $236 million in debt positions. On-chain data shows the attacker consolidated around 74,000 ETH post-exploit, extracting over $280 million in actual borrowed value.
Because the rsETH collateral backing those loans was no longer worth anything — the tokens were unbacked fabrications — the resulting debt positions are effectively unliquidatable. No liquidation bot can clear a position where the collateral has no real value. The bad debt simply sits on the protocol’s books, a permanent liability.
Technical Context — Why the Debt Is Unliquidatable
In DeFi lending, liquidations work by allowing third-party bots to repay an undercollateralized loan in exchange for seizing the collateral at a discount. This mechanism only functions if the collateral has genuine market value. Because the rsETH deposited as collateral by the attacker was minted without real backing, it now trades at a severe discount to its supposed peg — meaning liquidators would seize worthless tokens. Aave’s WETH reserve is now carrying approximately $196 million in debt it cannot recover through any standard mechanism.
Aave: Collateral Damage at the Largest Lender in DeFi
Aave did nothing wrong in a narrow technical sense. Its smart contracts were not compromised. Its own code did not fail. Aave’s founder Stani Kulechov was quick to clarify this on X, noting the exploit was entirely external and that Aave’s protocol had not been breached. But that distinction — sound code, catastrophic exposure — is precisely what makes the Kelp incident so instructive about the systemic risks embedded in modern DeFi.
Aave is the largest lending protocol in the ecosystem by total value locked, with over $26 billion deposited as of April 18. Ethereum alone holds $14.24 billion of the $17.82 billion in outstanding borrows across Aave’s 22-chain lending book. WETH — the exact asset the attacker borrowed — constitutes 39.49% of all loans on the protocol. The attack landed on the precise collateral-to-WETH pair that dominates Aave’s entire book.
The consequences were immediate and severe. Aave’s total value locked collapsed from $26.4 billion on April 18 to nearly $20 billion by Sunday morning — a $6.6 billion drop in under 24 hours, as depositors rushed to withdraw and the market priced in potential bad debt. The AAVE governance token fell approximately 16% over the same period.
Aave froze rsETH markets on both V3 and V4 within hours of the exploit. Initially, the protocol stated that its “Umbrella” reserve — a dedicated safety module designed to backstop bad debt scenarios — would cover any deficit. By Saturday evening, that language had softened considerably, with the team acknowledging they would “explore paths to offset the deficit.” The Umbrella reserve may not be large enough to cover the full $196 million shortfall, raising the prospect that staked AAVE token holders — who bear losses as a last resort — could face dilution.
Contagion Across the Ecosystem
The freeze cascade extended far beyond Aave. SparkLend halted its rsETH markets. Fluid froze rsETH collateral positions. Lido Finance paused further deposits into its earnETH product, which carries rsETH exposure, while carefully clarifying that its core stETH and wstETH products were entirely unaffected. Ethena, despite having no rsETH exposure, temporarily paused its own LayerZero OFT bridges as a precaution while the root cause was being identified — a bridge pause lasting roughly six hours.
The broader market impact was swift. Staked ETH derivatives stETH and wstETH fell approximately 4% as investors processed the news. rsETH itself broke sharply from its ETH peg as holders on more than 20 Layer 2 networks faced the prospect that the token’s reserve backing may have been permanently impaired. The question of whether rsETH holders on non-Ethereum networks can be made whole remains, as of publication, entirely unresolved.
“Liquid restaking tokens were whitelisted across every major lending protocol because they carried yield and represented a growing share of Ethereum’s locked value. The risk models priced them as if they would hold peg under normal conditions.”
The Broader Context: A DeFi Sector Under Siege
The KelpDAO exploit did not occur in isolation. It is the headline event in what security researchers are increasingly describing as a structural shift in how DeFi is being attacked. The Kelp incident cements 2026 as the worst year on record for DeFi security by cumulative losses. By mid-April, total losses across the sector had crossed $482 million across approximately 45 protocols — and this was before the KelpDAO drain was added to the tally.
The prior record holder for 2026’s largest exploit was the Drift Protocol attack on April 1, which cost the Solana-based perpetual futures exchange $285 million. In that case, attackers used social engineering to manipulate Security Council members into pre-signing transactions using Solana’s durable nonces feature — gaining administrative control and withdrawing real USDC and SOL within 12 minutes. Authorities later linked the attack to North Korea-affiliated actors.
Other notable incidents from the same 20-day period include: a domain hijacking attack on DEX aggregator CoW Swap ($1.2 million, April 14), a flash loan manipulation on Binance Smart Chain ($1.6 million), an oracle misconfiguration exploit targeting Silo Finance ($392,000, April 3), and a smart contract bug in bridge aggregator Dango ($410,000). Security firm Cyvers confirmed the Kelp attacker’s initial wallet was funded through Tornado Cash, the on-chain coin mixer, to cover gas fees and obscure origins.
What the incidents collectively illustrate is a profound evolution in attack vectors. Pure smart contract code exploits — the reentrancy bugs and integer overflow vulnerabilities of earlier DeFi eras — are no longer the dominant threat. Infrastructure-level attacks, including private key compromise, social engineering, compromised frontends, and cross-chain bridge manipulation, accounted for approximately 76% of losses in early 2026. AI-assisted phishing campaigns have reportedly scaled by an estimated 500% compared to the same period in 2025.
What This Means for Restaking and the Future of DeFi Collateral
The Kelp incident forces a reckoning with one of the most consequential decisions lending protocols made over the past two years: the wholesale acceptance of liquid restaking tokens as blue-chip collateral. rsETH, along with tokens from Ether.fi, Renzo, and Puffer, flooded into DeFi’s collateral frameworks because they represented real, yield-generating ETH — and because the restaking sector was growing at extraordinary speed, with EigenLayer attracting billions in deposits.
The implicit assumption in every risk model that whitelisted these tokens was that the peg would hold. That the backing would remain intact. That there would be no bridge failure, no minting exploit, no sudden decoupling between the receipt token and the real assets it was supposed to represent. The KelpDAO incident has now demonstrated that this assumption was not merely optimistic — it was catastrophically fragile, and it was exposed not by some exotic new vulnerability but by a forged message on a cross-chain bridge.
Cyvers CEO Deddy Lavid summarized the structural exposure bluntly: the incident shows the risks of composability in DeFi, where protocols are deeply connected. When a token’s backing collapses on one part of the infrastructure, every protocol that accepted it as collateral absorbs the impact — whether or not their own code was sound.
The immediate aftermath will likely include substantially tighter risk parameters for liquid restaking token collateral across major lending platforms, accelerated bridge security audits across the LRT ecosystem, and a broader industry debate about whether restaked Ether of any variety should be classified as equivalent to ETH itself for collateral purposes. KelpDAO has indicated it is working with LayerZero, its auditors, and external security researchers on a root cause analysis. As of publication, the exact mechanism by which the bridge’s validation logic was bypassed has not been publicly disclosed.
What Happens Next
For rsETH holders, the central question is redemption. With 116,500 tokens — 18% of total circulating supply — now unbacked, and with reserves previously held by the bridge now gone, the protocol faces a fundamental solvency challenge on its Layer 2 deployments. KelpDAO has deployed a temporary v2 pool for affected holders, though the economics of any recovery plan remain unclear.
For Aave, the path forward hinges on whether the Umbrella reserve can absorb the shortfall, whether the DAO votes to use treasury resources to offset remaining bad debt, or whether staked AAVE holders face dilution. The $6.6 billion TVL collapse may prove transitory if the protocol’s response is decisive; a prolonged period of uncertainty would be more damaging.
For the DeFi ecosystem broadly, the KelpDAO hack will be studied for years — not as an anomaly, but as a case study in how the sector’s greatest strength, the open, permissionless composability that allows protocols to build on each other, is also its deepest structural vulnerability. Until cross-chain bridges can be made reliably trustless, and until collateral risk frameworks account for the possibility that a token’s backing can evaporate in under an hour, no risk model in DeFi is complete.
— ◆ —
Update: April 20, 2026
Lazarus Group Attribution — North Korea Linked to the Attack
In the most significant development since the initial drain, LayerZero published a detailed post-mortem on April 20 shifting both the technical blame and the threat attribution squarely onto the record. LayerZero concluded the exploit stemmed entirely from Kelp’s own security choices — specifically its decision to run a 1-of-1 verifier configuration on its LayerZero bridge, meaning LayerZero Labs was the sole entity responsible for verifying cross-chain messages to and from the rsETH bridge. LayerZero’s public integration documentation and direct communications to Kelp had explicitly recommended a multi-verifier setup with redundancy, requiring consensus across several independent verifiers to confirm any message. Kelp did not implement this recommendation.
The mechanics of the attack, as LayerZero’s traffic logs now reveal, involved compromising two RPC nodes and deploying a distributed denial-of-service attack between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday. The DDoS forced a failover in the bridge’s infrastructure. Once that failover triggered, the compromised nodes told the sole verifier that a valid cross-chain message had arrived — and Kelp’s bridge released the 116,500 rsETH. The malicious node software then self-destructed, wiping binaries and local logs to complicate forensic analysis. LayerZero has stated it will no longer sign messages for any project still running a 1-of-1 verifier configuration.
Attribution — North Korea’s Lazarus Group
LayerZero’s post-mortem preliminarily attributes the attack to North Korea’s Lazarus Group — the same state-sponsored unit linked to the Drift Protocol exploit on April 1. If confirmed, Lazarus will have drained more than $575 million from DeFi in 18 days through two structurally different attack vectors: social engineering governance signers at Drift, and poisoning infrastructure RPCs at Kelp. The group appears to be adapting its playbook faster than DeFi protocols are hardening their defenses.
Aave’s Liquidity Crisis Deepens
What began as a bad debt problem has compounded into a full liquidity crisis. In the 48 hours following the exploit, Aave suffered $8.45 billion in total deposit outflows, driving the broader DeFi ecosystem’s total value locked down by $13.21 billion. The panic was not limited to rsETH holders — whales with unrelated positions fled the protocol en masse, pushing Aave’s ETH and WETH pools to 100% utilization.
When a lending pool reaches 100% utilization, withdrawals stop working. Every dollar deposited is already borrowed, leaving no idle liquidity for suppliers to redeem against. Depositors with USDT, USDC, and WETH positions found themselves trapped — unable to exit even though their assets had no direct rsETH exposure whatsoever. In a desperate secondary market response, some stranded users borrowed against their own locked stablecoin deposits at steep losses, accepting roughly 75 cents on the dollar just to extract any liquidity at all. Analysts at Spark estimated this dynamic drove a $300 million borrowing spike in USDT-collateralized positions in a single day.
A post on the Aave governance forum by a community member captured the mounting urgency around one underappreciated dimension: the bad debt is denominated in ETH, not dollars. The attacker borrowed approximately 126,000 ETH using the stolen rsETH as collateral. That debt is fixed in ETH terms. Aave’s Umbrella backstop and treasury reserves, however, are denominated in stablecoins. Every hour ETH price appreciates, the real cost of the shortfall grows — making speed of governance response a direct financial variable.
The Umbrella Gap and Governance Response
Aave’s Umbrella safety module — an automated backstop funded by protocol revenue and staked deposits — was designed for exactly this scenario. The mechanism allows staked aTokens to be slashed and burned to offset confirmed bad debt without requiring a governance vote, providing automated coverage. The problem is scale: as of mid-April 2026, the Umbrella reserve held an estimated $80–$100 million in assets, against a bad debt exposure of $196 million. The shortfall of roughly $96–$116 million cannot be covered automatically and will require explicit governance decisions.
The recovery waterfall, as described by The Defiant, runs in the following order: aWETH Umbrella stakers absorb the first slice via automatic slashing; WETH suppliers take a pro-rata haircut on remaining deposits; stkAAVE holders face potential governance-activated slashing for the next tranche; and finally the DAO treasury could fund a broader repayment proposal. None of these outcomes are comfortable. A governance proposal to slash a percentage of staked AAVE is being actively discussed, and stkAAVE holders are already pricing that risk.
On the governance front, the Aave Chan Initiative moved swiftly, announcing it was ending its Frontier staking program immediately in response to the wETH shortfall risk. Aave V4’s Security Council separately disabled supply and borrow on both the Core Hub and the Kelp E-Spoke, while a Risk Stewards proposal to reduce the WETH Slope1 — aimed at pulling new supply back into the pools — went live. A damaging governance detail also emerged: a proposal in January 2026 had raised the rsETH loan-to-value ratio to 93%, apparently without adequate bridge risk assessment, significantly amplifying the scale of the resulting bad debt.
Aave founder Stani Kulechov has maintained publicly that the protocol operated as designed and that its own contracts were not compromised. That distinction is technically accurate. But as one market observer noted: the risk models priced rsETH as if it would hold peg under normal conditions. None of them priced the scenario where the collateral goes to zero because a bridge on a chain Aave does not control gets poisoned on a Saturday afternoon.
— ◆ —
This article was originally compiled from on-chain data, blockchain investigator reports, and protocol statements published April 18–19, 2026, and updated on April 20, 2026 with new developments including LayerZero’s post-mortem, Lazarus Group attribution, and Aave’s ongoing liquidity and governance response. The situation remains active. Figures cited reflect best available reporting at time of each update.
KelpDAO has reportedly lost more than $280 million after attackers drained positions across multiple Decentralized Finance (DeFi) protocols on Ethereum and Arbitrum.
On-chain investigator ZachXBT flagged the incident on April 18, identifying six attacker-controlled wallets actively moving the stolen funds.
How the KelpDAO Attack Happened
Blockchain data shows the attacker wallets received initial funding through Tornado Cash, the privacy mixer, hours before the theft began.
The wallets then interacted with DeFi protocols, executing token approvals and swaps through KyberSwap and KelpDAO before converting all positions into ether (ETH).
“KelpDAO appears to have had $280M+ stolen one hour ago on Ethereum and Arbitrum. The attack addresses were funded via Tornado Cash,” ZachXBT wrote on Telegram.
Within roughly one hour, the attackers consolidated approximately 75,700 ETH, worth around $178 million at current prices, into a single wallet.
The remaining stolen value includes additional tokens and positions on Arbitrum. As of publication, no outflows from the consolidation wallet had been detected.
The pattern suggests a private-key compromise rather than a smart-contract exploit in any specific protocol.
The victim appears to have held significant DeFi exposure across both chains, and the attacker systematically withdrew and swapped those positions into raw ETH.
AAVE MULTISIG GUARDIAN FREEZES RSETH ON LENDING MARKETS: ONCHAIN
In January 2026 alone, a single phishing victim lost $284 million, accounting for over 70% of the month’s total crypto theft losses.
If confirmed at $280 million, this would rank among the largest individual wallet compromises on record.
Security analysts are expected to publish deeper on-chain analysis in the coming hours.
Elsewhere, reports also indicate that the Instagram account of Solana meme coin launchpad Pump.fun has been compromised.
“Any posts made from the official pump fun Instagram account should not be trusted. Ignore any and all posts made by the account until we have secured the account,” the team wrote.
Nevertheless, Pump.fun platforms remain operational and user funds are safe.