On April 18, 2026, an attacker linked to North Korea's Lazarus Group exploited KelpDAO's LayerZero bridge, minting 116,500 unbacked rsETH tokens worth $292 million in a single transaction. The attacker deposited 89,567 rsETH into Aave V3 as collateral and borrowed $190 million in WETH and wstETH ...
"Aave is my life's work and we're working nonstop to find the best possible outcome for users." — Stani Kulechov, Founder, Aave
On April 18, 2026, an attacker linked to North Korea's Lazarus Group exploited KelpDAO's LayerZero bridge, minting 116,500 unbacked rsETH tokens worth $292 million in a single transaction. The attacker deposited 89,567 rsETH into Aave V3 as collateral and borrowed $190 million in WETH and wstETH before the exploit was detected. Aave's total value locked fell from $26.4 billion to $18.6 billion within 48 hours as depositors fled, and the AAVE token dropped 18%.
The response that followed — a coalition called DeFi United — represents the first coordinated, multi-protocol recovery operation in DeFi history. Seven protocols pledged approximately 69,534 ETH (~$161 million), with total commitments exceeding $300 million. The operation's two-track technical plan, disclosed April 28, attempts to restore rsETH backing without socializing losses across holders. Whether it succeeds depends on governance votes that have not yet passed, frozen funds held by the Arbitrum Security Council, and untested bridge security patches.
This report examines the mechanics, precedents, and structural implications of the recovery effort.
At 17:35 UTC on April 18, the attacker targeted KelpDAO's LayerZero V2 bridge route between Unichain and Ethereum. The bridge relied on a 1-of-1 DVN (Decentralized Verifier Network) configuration — a single verification node securing cross-chain message authenticity. According to multiple incident reports, the attacker compromised two of LayerZero's verification servers and flooded backup servers with junk traffic, forcing the system to relay a forged cross-chain message.
The forged message authorized the minting of 116,500 rsETH tokens on Ethereum — approximately 18% of rsETH's total supply — with zero ETH backing. Within minutes, the attacker deposited roughly 89,567 rsETH into Aave V3 markets across Ethereum, Arbitrum, Base, Mantle, and Linea, then borrowed 82,650 WETH and 821 wstETH against the fabricated collateral.
The exploit is the largest single DeFi theft of 2026 and has been preliminarily attributed to North Korea's Lazarus Group. Unlike previous state-sponsored crypto thefts where voluntary return of funds remained a theoretical possibility, Lazarus Group — a sanctioned, state-directed actor — has never returned stolen assets.
The second-order effects exceeded the direct theft in scale. Aave's pooled lending architecture meant that the unbacked rsETH collateral sat in shared liquidity pools alongside legitimate deposits. When the exploit became public, depositors initiated a withdrawal cascade.
Quantified impact within 48 hours:
The Aave Guardian froze rsETH and wrsETH reserves across Ethereum Core, Arbitrum, Base, Mantle, and Linea. A proposal to pause AAVE token buybacks went live on April 28, formalizing a de facto halt in place since April 19.
According to NYDIG's analysis, the protocol faces between $123.7 million and $230.1 million in potential bad debt, depending on how losses are distributed. Under a uniform loss distribution (Scenario 1), each affected position absorbs approximately 15%. Under an isolated loss scenario (Scenario 2), L2 deployments absorb concentrated hits: Mantle at 71% of its WETH pool ($77.7 million), Arbitrum at 27% ($88.4 million), and Base at 23% ($47.5 million).
Three independent oversight organizations departed Aave in the weeks preceding the exploit — BGD Labs (April 1), the Aave Chan Initiative, and Chaos Labs (April 6, twelve days before the hack) — a timing that raises questions about institutional governance continuity.
DeFi United launched on April 23, five days after the exploit. It is led by Aave service providers and includes seven core protocol participants, each contributing ETH to a shared recovery fund. As of April 28, confirmed pledges total approximately 69,534 ETH (~$161 million).
Pledge breakdown by participant:
| Participant | Pledge (ETH) | Approximate USD | Structure | |---|---|---|---| | Mantle | 30,000 | ~$69.5M | Structured loan | | Aave DAO Treasury | 25,000 | ~$57.9M | Pending governance vote | | Stani Kulechov (personal) | 5,000 | ~$11.6M | Personal donation | | EtherFi | 5,000 | ~$11.6M | Direct pledge | | Lido | 2,500 stETH | ~$5.8M | Pending DAO vote | | Golem Foundation | 1,000 | ~$2.3M | Direct pledge | | Emilio Frangella (personal) | 500 | ~$1.2M | Personal donation | | BGD Labs | 250 | ~$0.6M | Direct pledge | | Ethena, Ink Foundation, others | Various | — | Amounts not fully disclosed |
Additional resources in the recovery:
The exchange ratio for recovery is set at 1.07 ETH per rsETH.
The technical plan, disclosed April 28, follows a two-track approach to restoring rsETH backing:
Track One — Staged Redeposit: Committed ETH is converted to rsETH in tranches and deposited into the RSETH_OFTAdapter contract. The coalition opted for staged deposits over a lump-sum approach to enable production validation at each step. Once complete, KelpDAO's bridge can resume full operation.
Track Two — Coordinated Liquidation: Governance-approved liquidations clear eight affected positions across Aave V3's Ethereum Core and Arbitrum markets, recovering roughly 13,000 ETH. An additional ~16,776 ETH is targeted through Compound liquidations. Execution requires temporary oracle adjustments through governance on both chains.
Recovered rsETH is transferred to a DeFi United-managed multisig, then redeemed through Kelp's standard process. LayerZero and KelpDAO have committed to implementing new security measures before the bridge restarts.
DeFi United is structurally distinct from every prior exploit recovery. Historical comparison:
| Exploit | Year | Loss | Recovery Mechanism | Timeline | |---|---|---|---|---| | Ronin Bridge | 2022 | $625M | Sky Mavis raised funding round | Months | | Wormhole | 2022 | $320M | Jump Trading injected own capital | Days | | Euler Finance | 2023 | $197M | Attacker returned funds after negotiation | Weeks | | KelpDAO/rsETH | 2026 | $292M | Multi-protocol coalition (DeFi United) | Ongoing |
The Wormhole case is the closest parallel: a forged-signature cross-chain exploit resolved by a single entity (Jump Trading) backstopping the entire loss. The difference is scale and structure. Wormhole's fix required one decision-maker. DeFi United requires governance votes from at least three DAOs (Aave, Lido, Compound), cooperation from the Arbitrum Security Council, and finalized terms on Mantle's structured loan.
The Euler case involved an attacker who eventually returned funds — a path functionally closed with Lazarus Group.
No prior DeFi exploit has produced a coordinated, multi-protocol mutual defense response. According to analysts, DeFi United sets three precedents: an informal mutual defense expectation among interconnected protocols; a framework for loss distribution across shared infrastructure; and a template for rapid coalition formation that did not exist before April 2026.
The exploit exposed a structural vulnerability in Aave's pooled lending architecture. In Aave V3, lenders supply into a shared liquidity pool. Any whitelisted collateral — ETH, wstETH, cbBTC, or rsETH — can borrow against the same pool under one blended rate and shared risk parameters. When rsETH's backing collapsed, the impairment propagated to every position in the pool.
Morpho's performance during the same event provides a direct counterfactual. Morpho uses an isolated-market design: its base layer (Morpho Blue, a 650-line immutable primitive) creates independent markets, while a curator layer (Morpho Vaults) allocates deposits across them. During the KelpDAO exploit, only $1 million of ETH was borrowed against rsETH on Morpho, contained to 2 of approximately 500 vaults with over $10,000 in deposits.
Aave's exposure: ~$196 million in bad debt. Morpho's exposure: ~$1 million. A 196:1 ratio from the same underlying event.
NYDIG's analysis identified additional architectural concerns in Aave: no loan recall mechanism to force borrower repayment; 100% utilization that locks depositors while accepting new deposits; an automatic rate algorithm that produced 4x increases with zero notification; and shared loss pools that expose unrelated positions to cross-collateral failures.
The January 2026 Aave governance vote that enabled e-mode for rsETH at 93% loan-to-value did not include a bridge risk assessment — a gap the community has since flagged as a contributing factor.
As of April 29, the DeFi United recovery plan depends on multiple governance outcomes:
Aave DAO: Must approve the 25,000 ETH treasury allocation and temporary oracle adjustments enabling liquidation of affected positions. A separate vote to pause AAVE buybacks went live April 28.
Compound DAO: A proposal to contribute up to 3,000 ETH is under consideration.
Lido DAO: Must approve the 2,500 stETH pledge.
Arbitrum Security Council: Must agree to release the 30,766 ETH frozen from the exploiter's address to DeFi United's recovery multisig.
Mantle: Must finalize terms on its 30,000 ETH structured loan.
Under NYDIG's Scenario 2, if governance votes fragment — mainnet users walk away whole while L2 users, particularly on Mantle, see rsETH collateral value cut by nearly 75%. The distributional politics of who pays are as significant as the technical recovery.
The concentration of voting power compounds the uncertainty. Aave Labs, the founding entity, holds significant governance influence, and the departure of three independent oversight bodies in the weeks before the exploit has left the governance landscape thinner than usual.
DeFi United represents an inflection point for decentralized finance governance. The $292 million KelpDAO exploit forced seven competing protocols to abandon the principle that each protocol's risk is its own problem. The mutual defense framework that emerged — voluntary, industry-funded, organized in five days — has no precedent in DeFi history.
The comparison to Wormhole (2022) is instructive. Jump Trading's unilateral $320 million backstop was faster and cleaner, but it required a single entity with deep capital and no governance constraints. DeFi United's multi-stakeholder approach is slower, dependent on at least five separate governance decisions, and exposes fundamental disagreements about loss allocation between mainnet and L2 users.
The architectural lesson is equally clear. Morpho's $1 million exposure versus Aave's $196 million from the identical event is not a function of better risk management — it is a structural outcome of isolated versus pooled market design. Whether this comparison accelerates a migration toward isolated architectures or simply adds a new risk parameter to pooled designs remains an open question.
What is not in question: the bridge vulnerability that enabled the exploit — a 1-of-1 DVN configuration securing $292 million in cross-chain value — represents a systemic design failure. The recovery may succeed. The governance votes may pass. But the single-verifier bridge architecture that made it possible remains deployed across multiple protocols.