April 2026 is the worst month for crypto theft since the $1.4 billion Bybit breach in February 2025. Across 12 incidents in 18 days, attackers drained $606 million from DeFi protocols. Two exploits — $285 million from Drift Protocol on Solana and $292 million from KelpDAO on Ethereum — account fo...
"Aave is my life's work and we're working nonstop to find the best possible outcome for users. I'm personally contributing 5,000 ETH to DeFi United as we continue working together with partners on formalizing more commitments." — Stani Kulechov, Founder, Aave
April 2026 is the worst month for crypto theft since the $1.4 billion Bybit breach in February 2025. Across 12 incidents in 18 days, attackers drained $606 million from DeFi protocols. Two exploits — $285 million from Drift Protocol on Solana and $292 million from KelpDAO on Ethereum — account for 95% of the damage. Both have been attributed by blockchain forensics firms Elliptic, TRM Labs, and Chainalysis to North Korea's Lazarus Group.
The fallout was systemic. Aave, the largest DeFi lending protocol, lost $8.45 billion in deposits within 48 hours. Broader DeFi TVL dropped $13 billion. A class action lawsuit was filed against Circle for allegedly failing to freeze stolen funds. Arbitrum's Security Council executed an emergency asset freeze that reignited the decentralization debate. The year-to-date theft total now stands at approximately $771.8 million across 47 incidents — attack frequency up 68% year-over-year.
None of the three major April exploits involved smart contract bugs. All three — Drift, KelpDAO, and the smaller $3.5 million Volo Protocol hack — relied on compromising off-chain infrastructure: social engineering of multisig signers, manipulation of RPC nodes, and stolen admin keys.
| Metric | Value | |--------|-------| | Total stolen (April 1–18) | $606 million | | Separate incidents (April) | 12 | | YTD 2026 theft total | ~$771.8 million | | YTD 2026 incidents | 47 | | Q1 2026 losses (pre-April) | $165.5 million | | YoY attack frequency increase | 68% | | Aave deposit outflows (48 hrs) | $8.45 billion | | Broader DeFi TVL decline | $13 billion | | Worst month since | February 2025 (Bybit, $1.4B) |
The contrast between Q1 and April is stark. Q1 2026 losses fell 88% year-over-year to $165.5 million, suggesting improved security posture. April erased that narrative entirely. The two Lazarus-linked exploits alone represent 3.5x the entire first quarter's cumulative losses.
Date: April 1, 2026
Amount stolen: $285 million
Chain: Solana
Attack vector: Social engineering + oracle manipulation + governance exploit
The Drift attack was not a code exploit. It was a months-long intelligence operation.
Attackers posed as a quantitative trading firm and cultivated relationships with members of Drift's Security Council over several weeks, according to Chainalysis's post-incident analysis. The objective: get council members to pre-sign transactions using Solana's "durable nonces" feature — a mechanism that allows transactions to be signed now and executed later without time expiry.
With the pre-signed authorizations in hand, the attackers executed a zero-timelock Security Council migration, removing the protocol's last governance safeguard. They then manufactured a fictitious asset — CarbonVote Token (CVT) — seeded it with a few thousand dollars in liquidity, wash-traded it to inflate its price, and used it as collateral within Drift's lending vaults. Drift's oracles treated CVT as legitimate collateral worth hundreds of millions. The vaults were drained in approximately 12 minutes.
Post-theft, the attackers consolidated assets and swapped into USDC and SOL, then bridged a portion to Ethereum using Circle's Cross-Chain Transfer Protocol (CCTP). According to Elliptic, approximately $230 million was moved through CCTP over several hours.
This is the second-largest exploit in Solana's history, behind only the $326 million Wormhole bridge hack in February 2022.
Date: April 18, 2026
Amount stolen: $292 million (116,500 rsETH)
Chain: Ethereum (via LayerZero bridge)
Attack vector: Off-chain infrastructure compromise + DDoS
KelpDAO's exploit targeted the infrastructure layer between chains, not the smart contracts themselves. According to Chainalysis's technical breakdown, the attackers compromised two internal RPC nodes operated by LayerZero and simultaneously launched a DDoS attack against an external RPC node. This forced LayerZero's Decentralized Verifier Network (DVN) to rely exclusively on the attacker-controlled nodes.
The compromised nodes fabricated block data showing that 116,500 rsETH had been burned on Unichain. No such burn occurred. But KelpDAO's bridge was configured with a single-verifier setup — a 1-of-1 DVN configuration — meaning no second verifier existed to flag the discrepancy. The Ethereum-side contract released the full 116,500 rsETH to attacker-controlled addresses.
The 116,500 rsETH represented approximately 18% of the token's circulating supply.
LayerZero issued a statement blaming KelpDAO's configuration, noting it had previously warned Kelp to adopt a multi-verifier setup. KelpDAO countered that LayerZero's default configuration settings were the root cause. The 116,500 rsETH was scattered across 20+ chains, complicating recovery.
KelpDAO's team did manage to pause contracts before a second attempted withdrawal of $95 million could execute.
Date: April 21, 2026
Amount stolen: $3.5 million
Chain: Sui
Attack vector: Admin key compromise via social engineering
Three days after KelpDAO, Volo Protocol on Sui lost $3.5 million from three vaults holding WBTC, XAUm, and USDC. Security firms GoPlus Security and ExVul confirmed the root cause was a compromised admin private key, obtained through social engineering — not a smart contract vulnerability.
The losses broke down to approximately $2.1 million in WBTC, $900,000 in XAUm, and $500,000 in USDC. Volo's team intercepted and blocked the attacker's attempt to bridge out 19.6 WBTC (~$2.1 million), froze $500,000 in assets through coordination with ecosystem partners, and pledged to cover all remaining user losses. The Sui Foundation assisted in the response.
While small relative to Drift and KelpDAO, the Volo exploit confirmed a pattern: April's attacks were targeting humans and infrastructure, not code.
Both the Drift and KelpDAO exploits have been attributed to North Korea's Lazarus Group by Elliptic, TRM Labs, and Chainalysis. The attribution is based on Tornado Cash origin of seed funds, deployment timestamps consistent with Pyongyang time zones, social engineering methodology consistent with prior Lazarus operations, and post-hack laundering speed and patterns.
Lazarus's cumulative crypto theft now stands at an estimated $6.75 billion since 2017, according to compiled industry data. In 2025 alone, DPRK-linked actors stole $2.02 billion — approximately 59% of all crypto stolen globally that year. The $1.5 billion Bybit exploit in February 2025 remains the largest single incident.
CertiK disclosed in April 2026 that Lazarus has deployed a new macOS-targeted malware kit dubbed "Mach-O Man," which targets crypto and fintech executives through fake meeting invitations. Victims are lured to spoofed Zoom, Microsoft Teams, or Google Meet pages and instructed to paste a terminal command to "fix a connection issue." The malware is modular, erases itself before detection, and has been attributed to Lazarus's Chollima division.
According to a now-disbanded U.N. panel of experts, illicit cyber activity accounts for approximately 40% of funding for North Korea's weapons programs.
The KelpDAO exploit produced a contagion event that tested DeFi's structural resilience.
The attacker deposited approximately 90,000 of the stolen rsETH into Aave as collateral across Ethereum and Arbitrum, borrowing roughly $190 million in ETH and other assets. When the exploit was discovered and rsETH's backing collapsed, Aave was left holding unbacked collateral and up to $230 million in potential bad debt.
According to CoinDesk, $8.45 billion in deposits left Aave within 48 hours. Bloomberg described the episode as "the decentralized-finance equivalent of a bank run." Broader DeFi TVL dropped $13 billion in two days, according to DeFi Llama data.
However, the data suggests capital rotation rather than capital flight. Spark Protocol's TVL jumped from $1.8 billion to $2.9 billion over the same weekend. USDC holdings on exchanges increased. Capital was repricing risk and moving to perceived safer venues — not exiting crypto entirely.
Much of Aave's ETH exposure was concentrated in looping strategies: depositing liquid restaking tokens, borrowing ETH, swapping for more restaking tokens, and repeating. A $292 million theft does not mechanically produce $13 billion in outflows unless a substantial portion of TVL consists of recycled collateral. The unwind confirmed how leveraged DeFi's deposits actually are.
The "DeFi United" recovery initiative, led by Aave service providers, raised approximately $160 million of the $200 million needed to cover Aave's bad debt as of April 26. Participants include Lido Finance, EtherFi, Consensys, Joe Lubin (who contributed 30,000 ETH), Mantle Network (30,000 ETH backstop), and Stani Kulechov personally (5,000 ETH).
Class action against Circle. On April 15, law firm Gibbs Mura filed a class action lawsuit on behalf of Drift Protocol investors, naming Circle Internet Financial as a defendant. The complaint alleges Circle knowingly permitted the attackers to move $230 million in stolen funds through USDC and its CCTP bridge over several hours without intervention — despite having frozen 16 unrelated business wallets in a separate civil matter just nine days prior. The case, if successful, could establish precedent for stablecoin issuer liability in exploit scenarios.
Arbitrum Security Council freeze. On April 21, nine of the Arbitrum Security Council's 12 members authorized an emergency freeze of 30,766 ETH ($71 million) held by the KelpDAO exploiter on Arbitrum One. The action was taken in coordination with law enforcement, and the Security Council acted before the exploiter could finalize a native bridge withdrawal back to Ethereum mainnet. The frozen funds were transferred to a governance-controlled wallet; accessing them now requires a full Arbitrum DAO vote.
The freeze reignited debate about Layer 2 centralization. A 9-of-12 multisig with the power to freeze any address on Arbitrum One is functionally indistinguishable from a centralized custodian, critics argued. Supporters countered that the freeze prevented $71 million from reaching a state adversary.
Bank Policy Institute response. The Bank Policy Institute published an analysis noting that DeFi lending platforms lack sufficient insurance to cover lender losses and that Aave's insurance fund was "apparently inadequate." BPI called on policymakers to consider these risks when drafting crypto ecosystem rules.
April's exploits revealed three systemic weaknesses:
1. Off-chain infrastructure is the primary attack surface. None of the three major exploits targeted smart contract logic. Drift was compromised through social engineering of human signers. KelpDAO was compromised through RPC node infiltration. Volo was compromised through a stolen admin key. The industry's investment in smart contract auditing has not kept pace with threats to the infrastructure surrounding those contracts.
2. Single points of failure persist in cross-chain infrastructure. KelpDAO's 1-of-1 DVN configuration meant one compromised verifier was sufficient to forge a cross-chain message worth $292 million. Bridge protocols remain the "fattest targets in DeFi," as one CoinDesk analysis put it. Bridges accounted for $2.8 billion in historical losses prior to April 2026.
3. DeFi leverage amplifies contagion. A $292 million theft produced $13 billion in TVL decline because deposit bases are heavily composed of recycled collateral from looping strategies. The leverage multiple is opaque, poorly measured, and creates bank-run dynamics in lending protocols when confidence breaks.
April 2026 demonstrates that DeFi's security problem is not primarily a code problem. It is an infrastructure and human-factors problem. Smart contract audits — the industry's primary security investment — address a shrinking share of the actual attack surface. The three exploits that defined April all bypassed audited code entirely.
The contagion dynamics are equally concerning. DeFi's composability — the feature that allows protocols to build on each other — is also the mechanism through which a single exploit in one protocol can cascade into billions of dollars of withdrawals across the ecosystem. The recycled-collateral leverage embedded in looping strategies means DeFi's headline TVL figures substantially overstate the amount of discrete capital at risk, while simultaneously understating the systemic fragility of the deposit base.
The recovery response — $300 million in pledged support, emergency asset freezes, cross-protocol coordination — demonstrates that DeFi can organize crisis responses. Whether those responses are consistent with decentralization's value proposition is a question the industry has not yet answered.