Crypto protocols lost $606 million to exploits in the first 18 days of April 2026 — 3.7 times the $165.5 million stolen across all of Q1. Two incidents account for 95% of the total: the $285 million Drift Protocol drain on April 1 and the $292 million KelpDAO bridge exploit on April 18. Both are ...
"Code risk and operational risk are not the same problem. Treating them as one is what the next $292 million will cost." — Jainil Vora, OpenZeppelin
Crypto protocols lost $606 million to exploits in the first 18 days of April 2026 — 3.7 times the $165.5 million stolen across all of Q1. Two incidents account for 95% of the total: the $285 million Drift Protocol drain on April 1 and the $292 million KelpDAO bridge exploit on April 18. Both are attributed to North Korea's Lazarus Group. Year-to-date theft now stands at $771.8 million across 47 incidents, a 68% year-over-year increase in attack frequency.
The KelpDAO breach triggered a $13.2 billion contraction in DeFi total value locked within 48 hours — a 45:1 contagion ratio on the stolen amount. Aave, the largest lending protocol, absorbed between $124 million and $230 million in bad debt after the attacker deposited unbacked rsETH as collateral. USDT and USDC borrow rates on Aave spiked to 14%. The incident has reignited a structural question that bridge exploits keep answering the same way: cross-chain infrastructure remains the single fattest target in Web3, responsible for roughly 40% of all crypto theft since 2021.
| Metric | Value | |--------|-------| | Total stolen (April 1-18) | $606 million | | Number of incidents | 12 | | Largest single exploit | $292 million (KelpDAO) | | Second largest | $285 million (Drift Protocol) | | Q1 2026 total losses | $165.5 million | | April vs. Q1 multiple | 3.7x | | 2026 year-to-date losses | $771.8 million | | 2026 incidents to date | 47 | | Same-period 2025 incidents | 28 | | YoY frequency increase | 68% | | Average incident cadence | One every 2.9 days |
April 2026 is the worst month for crypto exploits since the $1.4 billion Bybit breach in February 2025, according to data compiled by crypto.news and Analytics Insight. The two mega-hacks — Drift and KelpDAO — together represent approximately 75% of all 2026 year-to-date losses.
On April 18, 2026, an attacker drained 116,500 rsETH (approximately $292 million) from KelpDAO's LayerZero-powered cross-chain bridge. The attack window lasted roughly 80 minutes.
What happened, step by step:
No smart contract bug was exploited. No cryptographic primitive was broken. Every on-chain transaction appeared valid. According to OpenZeppelin's post-mortem, traditional security tools missed the attack entirely because the exploit lived in the off-chain verification layer, not in auditable code.
According to Chainalysis, the incident "underscores how even audited protocols remain vulnerable when single points of failure exist in supporting networks."
The aftermath produced a public dispute between LayerZero and KelpDAO over responsibility.
LayerZero's position: The protocol's co-founder Bryan Pellegrino stated on X that the team is working to "harden security across every possible vector for applications." LayerZero's incident statement blamed KelpDAO's decision to use a 1-of-1 DVN configuration despite prior recommendations to adopt multi-verifier security.
KelpDAO's response: KelpDAO countered that LayerZero's own quickstart guide and default GitHub configuration specify a 1/1 DVN setup. According to CoinDesk reporting, approximately 40% of protocols deployed on LayerZero use the same single-verifier configuration that was exploited. LayerZero's V2 OApp Quickstart documentation wires every pathway with one required DVN and no optional DVNs.
The dispute highlights a systemic problem. If the default configuration of a widely used cross-chain messaging protocol is insecure, the vulnerability is architectural, not a user error confined to one deployment.
The $292 million theft was the initial shock. The second-order effects were an order of magnitude larger.
Within 48 hours of the KelpDAO exploit, DeFi total value locked fell by $13.2 billion, according to CoinDesk. Aave alone saw $8.45 billion in deposit withdrawals over the same period. CryptoQuant characterized the event as the "worst DeFi liquidity crunch since 2024."
Aave's exposure: An incident report posted to Aave governance outlined two scenarios — $123 million in bad debt if losses are socialized across all rsETH holders, or up to $230 million if concentrated on Layer 2 deployments. USDT and USDC borrow rates on Aave hit 14% as depositors fled and borrowers scrambled.
The contagion ratio: For every $1 stolen from KelpDAO, approximately $45 of additional capital exited the DeFi sector within 48 hours. At least nine protocols took measurable damage from the single Kelp exploit, according to Finance Magnates reporting.
A $300 million borrowing spike on Aave signaled acute liquidity stress, according to CoinDesk market data. The pattern is consistent with a bank-run dynamic: depositors withdraw while borrowers increase demand simultaneously, collapsing available liquidity and resetting interest rates higher.
Seventeen days before KelpDAO, on April 1, Solana-based perpetual futures platform Drift Protocol was drained of $285 million. Security firm TRM Labs traced the attack to UNC4736, a unit within North Korea's Lazarus Group.
The Drift attack combined three vectors: a compromised admin key obtained through months of social engineering targeting team members, a fabricated token with manipulated oracle pricing, and the absence of governance timelocks. The drain was completed in under 12 minutes.
Together, Drift and KelpDAO represent $577 million stolen in 18 days by the same state-sponsored threat actor.
Both of April's mega-exploits are attributed to North Korea's Lazarus Group. The pattern is not new.
According to Chainalysis's Crypto Crime Report, DPRK-linked actors stole $2.02 billion in cryptocurrency in 2025 — a 51% year-over-year increase and approximately 60% of all global crypto theft that year. The February 2025 Bybit hack alone accounted for $1.5 billion. Cumulative DPRK crypto theft now exceeds $6.75 billion across roughly 270 documented incidents.
In 2026, Lazarus is linked to at least $577 million in theft through the Drift and KelpDAO exploits alone, representing roughly 75% of the year's total. Certik flagged a new Lazarus attack vector — the "Mach-O Man" technique — in late April 2026, suggesting operational capacity continues to expand.
The scale of state-sponsored theft raises a question about the economic sustainability of certain DeFi infrastructure. When a single threat actor can extract hundreds of millions per quarter, the implicit security tax on the system is substantial.
The KelpDAO exploit is the latest in a recurring pattern. According to compiled industry data, cross-chain bridges have lost more than $2.8 billion since 2021 — approximately 40% of all money stolen in Web3.
Major bridge exploits, historical:
| Year | Protocol | Amount Lost | |------|----------|-------------| | 2022 | Ronin Bridge | $625 million | | 2022 | Wormhole | $321 million | | 2022 | Nomad | $190 million | | 2026 | KelpDAO | $292 million | | 2026 | Drift Protocol* | $285 million |
*Drift was a DEX exploit, not a pure bridge exploit, but used cross-chain fund movement in the attack chain.
Bridges are vulnerable because they occupy a trust boundary between two independent consensus systems. They require off-chain infrastructure — oracles, verifiers, relayers — to attest that events on one chain correspond to reality on another. That off-chain layer is where attackers concentrate.
The KelpDAO exploit demonstrated this precisely. The smart contracts worked as designed. The oracle infrastructure feeding them did not. As OpenZeppelin noted, "spotting this type of exploit requires cross-chain invariant monitoring — continuously verifying that tokens released on a destination chain mathematically match tokens burned on the source chain."
KelpDAO: Contracts were paused in time to block a second $95 million theft. The Arbitrum Security Council, acting with law enforcement input, froze 30,766 ETH (approximately $71 million) held on Arbitrum One. However, the attacker moved approximately 75,700 ETH ($175 million) into Bitcoin via THORChain within 36 hours of the exploit, making further recovery difficult.
DeFi United: Aave founder Stani Kulechov pledged 5,000 ETH toward a coalition — branded "DeFi United" — to restore rsETH backing. Mantle Network contributed a 30,000 ETH backstop. Lido Finance and EtherFi joined the initiative. Total commitments reached approximately $161 million.
Volo Protocol: On April 21, Volo Protocol on Sui lost $3.5 million to a separate private key compromise, underscoring the breadth of the attack surface beyond bridges alone.
Broader industry: April's 12 incidents in 18 days represent an attack cadence that significantly outpaces historical norms. The sector recorded 47 incidents in the first four-and-a-half months of 2026, versus 28 in the same period of 2025.
April 2026 exposed a gap between how the DeFi industry assesses security and where actual risk resides. The KelpDAO exploit — $292 million drained without a single line of buggy code — is the clearest demonstration to date that smart contract audits, the standard security assurance mechanism, address only a fraction of the attack surface.
The contagion dynamics were equally instructive. A single bridge misconfiguration cascaded through the composability stack, draining $13.2 billion in TVL and stranding wrapped assets across 20 chains. The DeFi United bailout coalition, while notable for its speed, is a reactive mechanism. It does not resolve the structural vulnerability: cross-chain messaging systems that default to single-verifier configurations, off-chain infrastructure that escapes audit scope, and a state-sponsored adversary that has extracted $6.75 billion and shows no signs of stopping.
The economic implications are direct. If bridge infrastructure remains this fragile, the cost of capital for cross-chain DeFi will remain elevated. Insurance premiums, if priced accurately, would consume a significant portion of yield. The market is pricing this reality in real time — the $13.2 billion outflow is not panic, it is repricing.