DeFi Intel

KelpDAO rsETH Cross-Chain Bridge Exploit (April 18, 2026)

Date
2026-04-18
Loss
$292M
Category
Bridge / liquid-restaking exploit
Attack vector
Single-signer LayerZero DVN spoofed via compromised RPC infrastructure to mint 116,500 unbacked rsETH, weaponized as collateral on Aave
Attribution
Lazarus Group / DPRK TraderTraitor subgroup (attributed by LayerZero Labs and Chainalysis)

Overview

On April 18, 2026, the liquid-restaking protocol Kelp DAO was exploited for approximately 116,500 rsETH worth roughly $292M through a compromise of its LayerZero-powered omnichain bridge rather than its smart-contract code. The attacker did not exploit a Solidity bug in the rsETH OFT (Omnichain Fungible Token) contracts; instead they defeated the bridge's off-chain verification layer, which depended on a single Decentralized Verifier Network (DVN) operated by LayerZero Labs in a one-of-one configuration with no independent second verifier required to agree. By compromising internal RPC nodes and degrading external nodes with denial-of-service traffic, the attacker fed the verification layer fabricated records showing that rsETH had been burned on the source chain when no such burn had occurred, causing the destination chains to mint a corresponding amount of unbacked rsETH. Within minutes the freshly-minted, unbacked rsETH was deposited as collateral on Aave and used to borrow real wrapped ETH, converting a phantom mint into a draining of genuine protocol liquidity and leaving Aave with an estimated $177M-$230M of bad debt across its Ethereum and Arbitrum deployments. Kelp DAO's emergency pauser multisig froze the core contracts roughly 46 minutes after the successful drain, reverting two follow-up attempts that each carried a LayerZero packet seeking another tranche of rsETH worth approximately $95M-$100M. LayerZero Labs attributed the operation to the DPRK's Lazarus Group, specifically the TraderTraitor subgroup, and the incident became 2026's largest crypto exploit. The aftermath produced an industry-coordinated recapitalization (Aave's DeFi United initiative) and a five-week rsETH recovery program, and it reopened the long-running debate about whether cross-chain bridges secured by minimal verifier sets are an acceptable foundation for systemically-important collateral.

Timeline of events

At 17:35 UTC on April 18, 2026, an attacker submitted a crafted cross-chain message to Kelp DAO's LayerZero bridge that released approximately 116,500 rsETH on Ethereum mainnet with no corresponding burn on the source chain, an amount equal to roughly 18% of rsETH's circulating supply and worth approximately $292M at prevailing prices. The unbacked tokens were immediately routed into Aave V3, where they were deposited as collateral and used to borrow wrapped ETH, peeling genuine liquidity out of the lending protocol. Kelp DAO's monitoring detected the anomaly within minutes; the protocol's emergency pauser multisig froze the rsETH OFT and core deposit-and-redemption contracts on Ethereum and the protocol's layer-2 deployments at approximately 18:21 UTC, roughly 46 minutes after the initial drain, and blacklisted the attacker-controlled addresses. Two follow-up transactions, each carrying a LayerZero packet attempting to mint a further tranche of approximately 40,000 rsETH worth roughly $95M-$100M, both reverted after the pause. By approximately 19:00 UTC, Aave's risk stewards had frozen all rsETH and wrapped-rsETH reserves across V3 deployments, set their loan-to-value ratios to zero to prevent further borrowing against the tainted collateral, and adjusted interest-rate models to manage the resulting liquidity stress. The Arbitrum Security Council subsequently froze 30,766 ETH held in attacker-linked positions on Arbitrum One. CoinDesk, The Defiant, and Chainalysis published detailed reconstructions over the following days, with all converging on the single-DVN root cause and a DPRK attribution.

Attack mechanism

The mechanism is now well-documented through forensic work by Chainalysis and LayerZero Labs. Kelp DAO's rsETH was issued as a LayerZero OFT, meaning a single canonical supply is tracked across chains and movement between chains is mediated by burning on the source chain and minting on the destination chain. Whether a burn actually occurred is attested not by the destination chain itself but by an off-chain verification layer: in LayerZero's stack, one or more DVNs sign off on the validity of each cross-chain packet before it is delivered. Kelp DAO had configured its bridge with a single verifier, the LayerZero Labs DVN, in a one-of-one arrangement: no second, independent DVN had to agree before a packet was accepted as valid. This collapsed the security of a multi-billion-dollar collateral asset to the integrity of one verification pipeline. The attacker did not break the DVN's signing keys directly; instead they poisoned the data the verification layer relied upon, compromising internal RPC nodes that the pipeline queried and degrading external nodes with denial-of-service traffic so that the surviving, compromised nodes reported a burn of rsETH on the source chain (Unichain) that had never happened. With the verification layer now attesting to a fictitious burn, the destination chains dutifully minted 116,500 rsETH of fresh, unbacked supply. The exploit therefore lived entirely in the off-chain infrastructure that sat between the contracts and the truth, in the same conceptual gap that the Bybit and WazirX incidents exploited at the signing layer. The decisive amplification came from composability: because rsETH was an accepted, blue-chip collateral asset on Aave, the attacker could convert phantom tokens directly into a claim on real wrapped ETH, so the unbacked mint did not merely dilute rsETH holders, it socialized the loss onto a separate lending market and its depositors.

Root cause analysis

Three root causes compound. First, and most fundamental, the one-of-one DVN configuration created a single point of failure for an asset of systemic size. Bridge security in the LayerZero model is a function of how many independent verifiers must agree; a single verifier means a single compromised pipeline is sufficient, which is precisely what occurred. A multi-DVN configuration requiring agreement from independent operators would have forced the attacker to compromise several pipelines simultaneously. Second, the verification layer trusted RPC node responses without sufficient redundancy or cross-checking, so an attacker who could compromise internal nodes and degrade external ones could manufacture a false consensus about source-chain state. The denial-of-service component is notable: by removing honest data sources rather than only injecting false ones, the attacker reduced the surface that had to be actively falsified. Third, the systemic blast radius was a function of cross-protocol composability that no single protocol controlled. Kelp DAO did not decide that unbacked rsETH could be borrowed against on Aave; that capability emerged from rsETH's status as accepted collateral, and it meant a verification failure in one protocol became a solvency event in another. None of these is a Solidity bug, and that is the point: the rsETH contracts behaved exactly as written. The failure was in the trust assumptions of the surrounding off-chain and cross-protocol system, the recurring theme of the 2024-2026 era of crypto incidents in which audited on-chain code is defeated by compromised infrastructure around it.

Initial response and contagion to Aave

Kelp DAO's on-chain response was fast by the standards of the incident class: the 46-minute pause prevented the two follow-up mints worth a combined approximately $190M-$200M, materially capping the loss. But the damage from the first mint had already propagated into Aave, where the attacker had borrowed real wrapped ETH against the unbacked rsETH collateral, leaving the lending protocol with bad debt estimated at $177M to $230M across its Ethereum and Arbitrum markets. Aave's risk stewards froze the rsETH and wrapped-rsETH reserves, zeroed their loan-to-value ratios, and adjusted rate models within roughly ninety minutes of the exploit, and the Arbitrum Security Council froze 30,766 ETH of attacker-linked positions on Arbitrum One. The contagion dynamic dominated the first week's narrative: a verification failure in a restaking protocol had become a balance-sheet hole in the largest DeFi lending market, with downstream pressure on the AAVE token and on GHO, Aave's stablecoin, as the market priced in the possibility of socialized losses. On April 23, Aave launched an industry-wide recovery initiative branded DeFi United to recapitalize rsETH backing and absorb the Aave bad debt, raising approximately $160M with Mantle and the Aave DAO together contributing roughly 55,000 ETH and additional contributions from Ether.fi, Lido DAO, and Aave founder Stani Kulechov. The response template, an affected protocol plus a coordinated consortium of the largest DeFi participants stepping in to backstop systemic bad debt, echoed the institutional bridge-loan response that had stabilized Bybit in February 2025, but executed through DAO treasuries and protocol partners rather than corporate balance sheets.

Funds tracking and laundering

On-chain investigators and Chainalysis tracked the proceeds as the attacker attempted to extract value across more than twenty chains, with wrapped ETH and other assets stranded across the OFT's deployments after the pause fragmented the attacker's holdings. The laundering pattern showed the characteristic DPRK markers that have recurred across the Bybit, WazirX, and CoinDCX incidents: immediate fan-out across intermediate addresses, conversion of restaking derivatives back to native assets where redemption paths remained open, and routing through cross-chain liquidity venues rather than sanctioned mixers. The cross-chain fragmentation that resulted from minting unbacked rsETH across many destinations cut both ways: it complicated the attacker's consolidation and gave defenders, including the Arbitrum Security Council and cooperating venues, multiple choke points at which to freeze value. LayerZero Labs attributed the operation to the Lazarus Group's TraderTraitor subgroup based on infrastructure overlap and laundering-pattern analysis, consistent with the FBI's prior TraderTraitor designations and with Chainalysis and Elliptic attributions of the 2025 exchange thefts. The combination of the Arbitrum freeze, the DeFi United recapitalization, and the redemption-path closures meant that a substantial share of the nominal $292M was either frozen, stranded, or backfilled rather than cleanly extracted, in contrast to the high net-extraction rates of the pure exchange thefts.

Recovery and remediation

The recovery proceeded on two tracks. On the protocol track, the Kelp DAO team executed a multi-week program to re-establish a fully-backed rsETH supply, reconciling the phantom mint against genuine backing and redistributing recovered and contributed ETH; the team announced completion of a five-week rsETH recovery, with a final tranche of approximately 20,373 rsETH sent to the rsETH OFT adapter to close the operational portion of the plan. On the lending-market track, Aave's DeFi United initiative recapitalized the bad debt, and Aave's own liquidation of the hacker's remaining rsETH positions on Ethereum and Arbitrum recovered a further portion, leaving the protocol reported as roughly 10% short of full bad-debt recovery at one interim milestone before continued contributions and liquidations narrowed the gap. The architectural remediation was the most consequential: Kelp DAO and the broader LayerZero ecosystem moved decisively away from one-of-one DVN configurations for systemically-important assets toward multi-DVN setups requiring agreement from independent verifiers, and added redundancy and cross-checking to the RPC and data layers that verification depends upon. The incident also intensified scrutiny of which assets DeFi lending markets should accept as collateral, with risk frameworks increasingly distinguishing assets whose backing is verifiable on-chain from those whose backing depends on off-chain bridge attestations.

Industry implications

The KelpDAO exploit reshaped four areas of practice. First, it ended the tolerance for minimal verifier sets on bridges securing systemically-important collateral: the one-of-one DVN became a cautionary archetype, and multi-verifier configurations with independent operators became the expected baseline for omnichain assets of meaningful size. Second, it forced DeFi lending markets to internalize bridge risk as collateral risk: an asset is only as solvent as the weakest verification pipeline that can mint it, and accepting such an asset as collateral imports that pipeline's risk into the lending market. Aave's post-incident risk parameters increasingly gated bridge-dependent collateral. Third, it demonstrated that DeFi's composability, long celebrated as a feature, is also a contagion vector: a phantom mint in one protocol became real bad debt in another with no contractual relationship between them, and the industry's response (the DeFi United consortium) implicitly acknowledged that systemic bad debt now requires collective backstops analogous to the bridge loans that stabilize compromised exchanges. Fourth, it confirmed that the DPRK threat actor had successfully pivoted from signing-layer attacks on exchanges (Bybit, WazirX) to verification-layer attacks on cross-chain infrastructure, broadening the attack surface from custodial signing flows to the off-chain machinery of omnichain tokens. The practical effect is that bridge and restaking protocols now face the same elevated operational-security and infrastructure-redundancy expectations that the post-Bybit era imposed on exchange treasuries.

Verdict and lessons

KelpDAO is the canonical 2026 demonstration that a cross-chain asset's security is determined by its weakest verifier, not by the correctness of its on-chain contracts, and that composability can turn a verification failure in one protocol into a solvency crisis in another. The rsETH contracts were correct; the LayerZero packets were processed exactly as the protocol's configuration permitted; and yet $292M of unbacked supply was minted and $177M-plus of real value was extracted from a separate lending market. The lessons are concrete. First, any bridge securing systemically-important collateral must require agreement from multiple independent verifiers; a one-of-one DVN is a single point of failure that no audit of the on-chain code can mitigate. Second, the data sources that off-chain verification relies upon (RPC nodes, oracles, indexers) are part of the trust boundary and must be redundant, cross-checked, and resistant to denial-of-service degradation, because an attacker who can remove honest data sources needs to falsify less. Third, lending markets must treat bridge-dependent collateral as importing the bridge's risk, gating loan-to-value and supply caps accordingly, because an unbacked mint elsewhere becomes the lender's bad debt. Fourth, the industry now requires pre-arranged systemic backstops: the DeFi United consortium worked, but it was improvised under crisis conditions, and the recurrence of nine-figure exploits argues for standing recapitalization mechanisms. For the threat-model picture, KelpDAO closes any remaining assumption that DPRK activity is confined to exchange custody and opens the chapter in which omnichain verification infrastructure is a first-class target.

Recovery

Kelp DAO completed a five-week rsETH recovery program, with a final tranche of ~20,373 rsETH sent to the rsETH OFT adapter to close the operational plan. Aave's DeFi United initiative raised ~$160M (Mantle and Aave DAO contributing ~55,000 ETH combined, plus Ether.fi, Lido DAO, and Stani Kulechov) to recapitalize bad debt; Aave's liquidation of the hacker's rsETH positions on Ethereum and Arbitrum recovered a further portion. Arbitrum Security Council froze 30,766 ETH of attacker-linked positions. Two follow-up mint attempts worth ~$190M-$200M combined were reverted by the 46-minute emergency pause.

Key lessons

  • Bridges securing systemically-important collateral must require agreement from multiple independent verifiers; a one-of-one DVN is a single point of failure no on-chain audit can mitigate
  • The data sources off-chain verification relies on (RPC nodes, oracles, indexers) are part of the trust boundary and must be redundant, cross-checked, and DDoS-resistant
  • Lending markets must treat bridge-dependent collateral as importing the bridge's risk, gating loan-to-value and supply caps accordingly
  • The industry needs standing systemic-backstop mechanisms; the DeFi United consortium worked but was improvised under crisis conditions
  • DPRK threat activity now targets omnichain verification infrastructure, not only exchange custody; bridge and restaking protocols face exchange-grade operational-security expectations

Frequently asked questions

What happened in the KelpDAO rsETH Cross-Chain Bridge Exploit?

Kelp DAO lost ~116,500 rsETH (~$292M) on April 18, 2026 when an attacker defeated its LayerZero bridge's single one-of-one DVN by compromising RPC nodes and DDoS'ing external nodes to fake a source-chain burn, minting unbacked rsETH that was immediately used as Aave collateral to borrow real wrapped ETH and leaving Aave with ~$177M-$230M bad debt. A 46-minute emergency pause reverted two follow-up mints worth ~$190M-$200M; the Arbitrum Security Council froze 30,766 ETH. LayerZero attributed the operation to Lazarus Group's TraderTraitor subgroup. Aave's DeFi United consortium raised ~$160M to recapitalize and Kelp DAO completed a five-week rsETH recovery. 2026's largest crypto exploit; the canonical case that a cross-chain asset is only as solvent as its weakest verifier and that composability turns one protocol's verification failure into another's bad debt.

How much was lost?

Approximately $292M was lost on 2026-04-18.

How did the attack work?

Single-signer LayerZero DVN spoofed via compromised RPC infrastructure to mint 116,500 unbacked rsETH, weaponized as collateral on Aave

Who was responsible?

Lazarus Group / DPRK TraderTraitor subgroup (attributed by LayerZero Labs and Chainalysis)

Were the funds recovered?

Kelp DAO completed a five-week rsETH recovery program, with a final tranche of ~20,373 rsETH sent to the rsETH OFT adapter to close the operational plan. Aave's DeFi United initiative raised ~$160M (Mantle and Aave DAO contributing ~55,000 ETH combined, plus Ether.fi, Lido DAO, and Stani Kulechov) to recapitalize bad debt; Aave's liquidation of the hacker's rsETH positions on Ethereum and Arbitrum recovered a further portion. Arbitrum Security Council froze 30,766 ETH of attacker-linked positions. Two follow-up mint attempts worth ~$190M-$200M combined were reverted by the 46-minute emergency pause.

Related