← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] $292M KelpDAO Hack Drains $13B From DeFi

Zephyra|April 21, 2026|BPF
EXECUTIVE SUMMARY

A single exploit drained $292 million from KelpDAO's rsETH bridge on April 18, 2026, and within 48 hours, $13.21 billion in total value locked had exited DeFi protocols across all top 20 chains. The contagion ratio — $45 of capital flight for every $1 stolen — is the highest recorded in a DeFi se...

"The exploit was external. Aave's contracts were not compromised. All protocol logic, including supply, repayment, and liquidation mechanics, continued to function as designed throughout the event." — Stani Kulechov, Founder, Aave

Executive Summary

A single exploit drained $292 million from KelpDAO's rsETH bridge on April 18, 2026, and within 48 hours, $13.21 billion in total value locked had exited DeFi protocols across all top 20 chains. The contagion ratio — $45 of capital flight for every $1 stolen — is the highest recorded in a DeFi security incident since the Terra collapse of 2022. Nine lending protocols froze rsETH markets. Aave alone shed $8.45 billion in deposits. Arbitrum's Security Council froze $71 million in stolen ETH through an emergency 9-of-12 vote.

The incident exposes a structural vulnerability in DeFi's collateral stack: liquid restaking tokens (LRTs), designed to compound yield through EigenLayer's restaking mechanism, have become deeply embedded as collateral across lending protocols. When one LRT's backing was compromised, the contagion propagated through every protocol that accepted it. The restaking sector, which held approximately $16.26 billion in TVL entering April, now faces a reckoning over single-point-of-failure infrastructure, collateral concentration, and the speed at which cross-chain composability can transmit risk.

Table of Contents

  1. The Attack: Anatomy of a $292 Million Bridge Exploit
  2. Contagion Mechanics: How $292M Became $13B
  3. Aave's Bad Debt Exposure: Two Scenarios
  4. The Nine-Protocol Freeze
  5. Arbitrum's Emergency Governance Action
  6. Liquid Restaking: The Collateral Layer That Failed
  7. The LayerZero–KelpDAO Blame Dispute
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Attack: Anatomy of a $292 Million Bridge Exploit

On Saturday, April 18, 2026, attackers drained 116,500 rsETH — approximately 18% of the token's 630,000 circulating supply — from KelpDAO's LayerZero-powered cross-chain bridge. The stolen tokens were valued at approximately $292 million at the time of extraction.

KelpDAO operates as a liquid restaking protocol built on EigenLayer. Users deposit staked ETH, the protocol routes it through EigenLayer to earn additional yield on top of standard Ethereum staking rewards, and issues rsETH as a tradeable receipt token. That receipt token had been widely adopted as collateral across DeFi lending markets.

The attack vector was the bridge's verifier configuration. KelpDAO's rsETH bridge relied on a single Decentralized Verifier Network (DVN) through LayerZero's infrastructure — a 1-of-1 configuration where LayerZero Labs was the sole entity verifying cross-chain messages. The attackers, whom LayerZero preliminarily attributed to North Korea's Lazarus Group, compromised two RPC nodes and executed a DDoS attack to force failover. This tricked LayerZero's verifier into approving a fraudulent cross-chain transaction, triggering KelpDAO's bridge to release 116,500 rsETH to an attacker-controlled address without burning any tokens on the source chain.

Industry best practice for LayerZero-powered bridges requires a multi-DVN setup — multiple independent verifiers that must reach consensus before approving cross-chain messages. KelpDAO's single-DVN configuration created a unilateral point of failure.

After extracting the rsETH, the attacker deposited 89,567 rsETH into Aave V3 markets on Ethereum and Arbitrum as collateral, borrowing approximately 82,650 WETH and 821 wstETH. Additional positions were opened on Compound V3 and Euler, bringing total borrowing across lending protocols to approximately $236 million.

Contagion Mechanics: How $292M Became $13B

The $292 million drain produced $13.21 billion of TVL outflows within 48 hours, according to CoinDesk data. This 45:1 contagion ratio — for every dollar stolen, $45 of additional capital exited DeFi — marks one of the most severe contagion events in DeFi history.

The transmission mechanism operated through three channels:

1. Collateral Depegging. With 18% of rsETH supply suddenly unbacked, the token's exchange rate against ETH broke. CryptoRank recorded a 72.6% drop in rsETH price within 24 hours. CoinMarketCap listed rsETH at $1,970.36, down from its pre-exploit peg tracking ETH at approximately $2,300. The depeg triggered automated liquidation processes across lending platforms that held rsETH as collateral.

2. Lending Protocol Bank Run. As news spread, depositors across all DeFi lending protocols — not just those exposed to rsETH — began withdrawing funds. Aave's TVL dropped from approximately $26 billion to $17.95 billion, a loss of $8.45 billion, within two days. A $300 million borrowing spike on Aave signaled acute liquidity stress as remaining depositors sought to exit or hedge. The AAVE token fell 16%.

3. Cross-Chain Capital Flight. The exploit affected rsETH stranded across 20 chains. DeFi TVL dropped on all top 20 chains simultaneously, according to BitcoinEthereumNews. The sell-off was indiscriminate — protocols with zero rsETH exposure saw withdrawals as depositors repriced DeFi risk broadly.

Total DeFi TVL fell from $99.5 billion to $86.3 billion in two days, a 13.3% decline sector-wide.

Aave's Bad Debt Exposure: Two Scenarios

On April 20, Aave Labs and risk management firm LlamaRisk published a joint incident report quantifying Aave's exposure. The report outlined two scenarios depending on how KelpDAO allocates the shortfall:

Scenario 1 — Socialized Losses. If losses are spread across all rsETH holders proportionally, the token would face an estimated 15% permanent depegging. This would generate approximately $123.7 million in bad debt for Aave — positions where the collateral value falls below the loan value with no borrower incentive to repay.

Scenario 2 — Layer-2 Isolated Losses. If losses are confined to rsETH on Layer 2 networks (where the exploit originated), bad debt rises to approximately $230.1 million. Under this scenario, the impact concentrates heavily: Mantle would absorb a 71.45% WETH shortfall and Arbitrum a 26.67% shortfall.

The Aave DAO treasury holds $181 million in assets: $62 million in Ethereum-correlated holdings, $54 million in AAVE tokens, and $52 million in stablecoins. Under Scenario 2, the bad debt would exceed total treasury holdings.

Aave's own smart contracts were not compromised. The protocol froze rsETH markets across V3 and V4 deployments within hours, set rsETH loan-to-value ratios to zero, and halted new borrowing against the asset. All core functions — supply, repayment, and liquidation — continued operating.

The Nine-Protocol Freeze

Nine DeFi protocols froze rsETH markets following the exploit, according to CoinEdition. The affected protocols include:

  • Aave — Froze rsETH on V3 and V4 across all deployments. Bore the largest exposure at $196 million in protocol-specific bad debt.
  • SparkLend — Froze rsETH markets. Reported zero direct exposure.
  • Fluid — Froze rsETH markets.
  • Upshift — Froze rsETH markets.
  • Compound V3, Euler, and Sentora — Had direct exposure from attacker borrowing positions.

The speed of the freeze response — hours rather than days — reflected lessons learned from previous DeFi incidents. However, the freezes also trapped legitimate rsETH holders who could no longer withdraw or manage their positions, creating a secondary liquidity crisis.

Arbitrum's Emergency Governance Action

On April 20, 2026, at 11:26 PM ET, Arbitrum's Security Council executed an emergency action to freeze 30,766 ETH (approximately $71 million) linked to the exploit. The freeze passed with 9 of 12 council members voting in favor.

The Security Council stated it acted on law enforcement input regarding the exploiter's identity and executed the freeze "without impacting any Arbitrum users or applications." Any movement of the frozen ETH now requires a full Arbitrum DAO governance vote, in coordination with legal authorities.

However, the attacker moved 75,700 ETH (approximately $175 million) across two new wallet addresses on April 21, just hours after the Arbitrum freeze was announced, according to TradingView data. This suggests the majority of stolen funds remain mobile.

The Arbitrum intervention raises governance questions. A Layer 2 security council unilaterally freezing user assets — even stolen ones — demonstrates the centralization inherent in current L2 architectures. The council's ability to act without a DAO vote relies on emergency powers that were designed for protocol-level threats, not third-party exploit recovery.

Liquid Restaking: The Collateral Layer That Failed

The KelpDAO exploit is the first major test of liquid restaking tokens as DeFi collateral — and the results are concerning.

The liquid restaking sector entered April 2026 with approximately $16.26 billion in TVL across the EigenLayer ecosystem, with 4.65 million ETH utilized in restaking frameworks, according to CoinLaw. The major LRT protocols by TVL: ether.fi at $7.83 billion, Renzo at $3.3 billion, and KelpDAO (Kernel DAO) at over $2 billion.

LRTs compound risk in ways that traditional collateral does not. A standard ETH deposit in a lending protocol carries Ethereum consensus risk. An LRT like rsETH carries: Ethereum consensus risk, EigenLayer slashing risk across multiple Actively Validated Services (AVSs), the issuing protocol's smart contract risk, and cross-chain bridge risk if the token is used on Layer 2 networks.

EigenLayer's own history illustrates this compounding dynamic. After enabling slashing on April 17, 2025, EigenLayer's TVL fell from over $15 billion to approximately $7 billion by late 2025, according to Medium analysis. The market had already repriced restaking risk once — but lending protocols continued accepting LRTs as collateral without proportional risk adjustments.

The multiplicative slashing exposure is substantial. A validator restaked across five AVSs, each with a 1% annual slashing probability, faces roughly 5% compound risk — assuming independence between AVS failures, which real-world correlation patterns do not support.

The LayerZero–KelpDAO Blame Dispute

A public dispute between LayerZero Labs and KelpDAO has emerged over responsibility for the exploit.

LayerZero's position: KelpDAO chose to use a single-verifier (1-of-1 DVN) configuration despite LayerZero's public integration checklist and direct communications recommending a multi-verifier setup with redundancy. LayerZero attributed the attack to North Korea's Lazarus Group.

KelpDAO's position: The compromised single-verifier setup relied on LayerZero's own infrastructure and default settings rather than an outlier configuration KelpDAO chose against advice. KelpDAO claims LayerZero's defaults are what "actually caused the $290 million disaster," per CoinDesk reporting.

The dispute highlights a systemic governance gap in cross-chain infrastructure. When a bridge protocol provides default configurations that do not meet security best practices, and an application protocol deploys using those defaults, liability allocation is ambiguous. Neither party's contracts defined responsibility for bridge security failures, leaving resolution to legal proceedings or community governance.

Key Takeaways

  • $292 million stolen from KelpDAO's rsETH bridge on April 18, producing $13.21 billion in DeFi TVL outflows within 48 hours — a 45:1 contagion ratio.
  • Aave faces $124M–$230M in bad debt depending on how KelpDAO allocates the shortfall, against a $181 million DAO treasury.
  • Nine DeFi protocols froze rsETH markets. The freeze contained further lending losses but trapped legitimate holders.
  • Arbitrum's Security Council froze $71M in stolen ETH through a 9-of-12 emergency vote, but the attacker moved $175M to new wallets hours later.
  • rsETH dropped 72.6% in 24 hours. Approximately 18% of circulating supply was extracted unbacked.
  • The 1-of-1 DVN bridge configuration created a single point of failure that enabled the entire exploit. LayerZero and KelpDAO dispute responsibility.
  • Liquid restaking tokens as DeFi collateral carry compounded risk layers — consensus, slashing, smart contract, and bridge risk — that current lending protocol risk models do not adequately price.
  • Lazarus Group attribution by LayerZero, if confirmed, would make this the third major DPRK-linked DeFi exploit of 2026 following the $285 million Drift Protocol hack.

Conclusion

The KelpDAO exploit is not simply a security incident — it is a stress test of DeFi's collateral architecture. The $292 million loss itself, while substantial, is secondary to the $13.21 billion in capital that fled the sector within two days. The 45:1 contagion ratio demonstrates that DeFi's interconnected collateral chains transmit risk faster and wider than the protocols themselves can respond.

Liquid restaking tokens were designed to compound yield. They also compound risk. When rsETH was accepted as collateral across nine or more lending protocols on multiple chains, the failure of one bridge created simultaneous bad debt positions across the entire lending stack. No individual protocol's risk parameters accounted for this correlated exposure.

The incident will likely accelerate three developments: mandatory multi-verifier configurations for cross-chain bridges, stricter LRT collateral requirements in lending protocols (higher liquidation thresholds, lower LTV ratios, isolated risk pools), and a re-examination of whether Layer 2 security councils should have unilateral asset-freezing powers.

For the liquid restaking sector's $16.26 billion TVL, the question is whether protocols can rebuild confidence in LRT collateral without structural changes to how bridge security and cross-protocol risk concentration are governed. The data suggests the market is not waiting for an answer — it is withdrawing.

Sources & References

  1. Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains — CoinDesk, April 19, 2026
  2. Aave could face up to $230M in losses after Kelp DAO bridge exploit triggers DeFi chaos — CoinDesk, April 20, 2026
  3. DeFi TVL drops more than $13 billion in two days following Kelp DAO hack — CoinDesk, April 20, 2026
  4. Aave records $6 billion TVL drop as Kelp hack exposes structural risk at DeFi lender — CoinDesk, April 19, 2026
  5. Arbitrum freezes $71 million in ether tied to Kelp DAO exploit — CoinDesk, April 21, 2026
  6. rsETH Incident Report — LlamaRisk / Aave Governance — Aave Governance Forum, April 20, 2026
  7. A $300 million borrowing spike on Aave signals liquidity crunch after exploit — CoinDesk, April 20, 2026
  8. Nine DeFi Protocols Frozen After $293 Million KelpDAO rsETH Exploit — CoinEdition, April 19, 2026
  9. Kelp DAO hits back at LayerZero for trying to shift the blame — CoinDesk, April 20, 2026
  10. LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus — CoinDesk, April 20, 2026
  11. DeFi sheds $13 billion in TVL following $290 million KelpDAO hack — Sherwood News, April 20, 2026
  12. KelpDAO exploiter moves 75,700 ETH across two new wallets after Arbitrum freeze — TradingView/Coinpedia, April 21, 2026
  13. Liquid Staking and Restaking Adoption Statistics 2026 — CoinLaw, 2026
  14. DeFi Contagion Risk in 2026: Inside the Kelp DAO–Aave Crisis — FinanceFeeds, April 2026
  15. Bitcoin bounces above $76,000 as DeFi suffers $14 billion exodus after KelpDAO hack — CoinDesk, April 20, 2026