← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Kelp DAO's $292M Bridge Exploit Spreads Across DeFi

Zephyra|April 18, 2026|BPF
EXECUTIVE SUMMARY

An attacker drained 116,500 rsETH — approximately $292 million and 18% of the token's 630,000-unit circulating supply — from Kelp DAO's LayerZero-powered cross-chain bridge at 17:35 UTC on Saturday, April 18, 2026. The exploit is now the largest DeFi theft of 2026, surpassing the $285 million Dri...

"Wish I had better news but looks like WETH on Aave is fucked. Withdraw if you can but likely too late." — 0xQuit, Ethereum Developer

Executive Summary

An attacker drained 116,500 rsETH — approximately $292 million and 18% of the token's 630,000-unit circulating supply — from Kelp DAO's LayerZero-powered cross-chain bridge at 17:35 UTC on Saturday, April 18, 2026. The exploit is now the largest DeFi theft of 2026, surpassing the $285 million Drift Protocol loss on April 1.

The attacker spoofed LayerZero's cross-chain messaging validation, tricking the bridge into releasing the full rsETH reserve to an attacker-controlled address funded via Tornado Cash. Kelp's emergency pauser multisig froze core contracts 46 minutes later at 18:21 UTC. Two follow-up drain attempts at 18:26 and 18:28 UTC — each targeting an additional 40,000 rsETH (~$100 million) — reverted against the frozen contracts.

The stolen rsETH was then deposited as collateral on Aave V3, where the attacker borrowed $236 million in Wrapped Ether (WETH). Because the drained rsETH no longer has any underlying backing, those borrow positions are effectively unliquidatable, leaving Aave's WETH reserve carrying unrecoverable bad debt. The AAVE token fell approximately 10% in the hours following the exploit. Aave, SparkLend, Fluid, Lido Finance, and Ethena all froze or paused rsETH-related markets within hours.

Table of Contents

  1. The Exploit: How It Happened
  2. Timeline of Events
  3. Downstream Contagion: Aave's Bad Debt Problem
  4. Protocol Responses and Market Freezes
  5. The Stranded-Asset Problem: 20 Chains, No Reserve
  6. Bridge Exploits in Context
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Exploit: How It Happened

Kelp DAO operates a liquid restaking protocol that accepts user-deposited ETH, routes it through EigenLayer for additional yield on top of standard Ethereum staking rewards, and issues rsETH as a tradeable receipt token. Prior to the exploit, Kelp DAO held $1.07 billion in total value locked and was the second-largest participant in EigenLayer's ecosystem, according to Crypto Briefing.

The protocol used a LayerZero-powered bridge to distribute rsETH across more than 20 blockchains — including Base, Arbitrum, Linea, Blast, Mantle, and Scroll. The bridge on Ethereum held the master reserve of rsETH backing all wrapped versions on those L2 networks.

The attacker exploited a flaw in LayerZero's cross-chain messaging validation logic. According to CoinDesk, the attacker tricked LayerZero's messaging layer into believing a valid instruction had arrived from another network. This spoofed message triggered the bridge to release 116,500 rsETH — approximately $292 million at prevailing ETH prices — to the attacker's address. The attacker had pre-funded wallets through Tornado Cash to obscure origin.

Kelp and LayerZero have not disclosed the specific root cause. Kelp acknowledged in a post at 20:10 UTC — nearly three hours after the drain — that it was investigating with LayerZero, Unichain, auditors, and security specialists.

Timeline of Events

| Time (UTC) | Event | |---|---| | 17:35 | Attacker drains 116,500 rsETH ($292M) from Kelp bridge | | 18:21 | Kelp emergency pauser multisig freezes core contracts (46 min response) | | 18:26 | First follow-up drain attempt (40,000 rsETH / ~$100M) — reverts | | 18:28 | Second follow-up drain attempt (40,000 rsETH / ~$100M) — reverts | | ~19:44 | ZachXBT flags the exploit publicly | | 20:10 | Kelp DAO posts first public acknowledgment on X | | Within hours | Aave freezes rsETH on V3 and V4; SparkLend, Fluid freeze rsETH markets | | Within hours | Lido pauses earnETH deposits (stETH/wstETH unaffected) | | Within hours | Ethena pauses LayerZero OFT bridges as precaution; confirms 101%+ overcollateralization |

The 46-minute gap between drain and contract freeze is notable. The two failed follow-up attempts suggest the attacker had pre-staged additional LayerZero packets targeting a cumulative $492 million drain, but the freeze blocked $200 million of the intended haul.

Downstream Contagion: Aave's Bad Debt Problem

The exploit did not stop at Kelp. The attacker immediately weaponized the stolen rsETH against DeFi's largest lending protocol.

Step 1: Deposit unbacked rsETH as collateral. The attacker supplied the 116,500 stolen rsETH tokens into Aave V3 lending pools on Ethereum and Arbitrum.

Step 2: Borrow WETH against it. According to blockchain.news, the attacker borrowed $236 million in WETH against the rsETH collateral.

Step 3: Exit with real value. The WETH borrowed represents actual, fungible value. The rsETH left behind as collateral is now unbacked — the reserve that gave it value was the very bridge reserve that was drained.

The result: Aave V3's WETH reserve now carries approximately $236 million in bad debt from positions that cannot be liquidated through normal mechanisms. The collateral (rsETH) has no underlying assets to redeem against. Standard liquidation — where a bot repays the debt and seizes discounted collateral — fails because no rational actor would buy unbacked rsETH.

Aave's Umbrella system, which replaced the legacy Safety Module in late 2025, is designed for this scenario. Users who staked aWETH in the Umbrella vault face automatic slashing to cover the deficit. Once the slashing cycle completes, remaining WETH suppliers should regain partial withdrawal access. Full recovery is not guaranteed. Depositors may face a haircut on their positions.

The AAVE token dropped approximately 10% as the market priced the potential bad debt exposure. Aave founder Stani Kulechov stated the exploit was "external" and that "Aave's contracts were not compromised."

Protocol Responses and Market Freezes

At least six major protocols took defensive action within hours:

| Protocol | Action Taken | |---|---| | Aave | Froze rsETH markets on V3 and V4 | | SparkLend | Froze rsETH markets | | Fluid | Froze rsETH markets | | Lido Finance | Paused earnETH deposits (stETH/wstETH unaffected) | | Ethena | Paused LayerZero OFT bridges; confirmed 101%+ overcollateralization | | Upshift | Confirmed zero rsETH exposure; monitoring situation |

The pattern of freezes reflects how deeply rsETH had been integrated as collateral across Ethereum's lending stack. A single bridge failure cascaded into market freezes across multiple independent protocols within hours — a systemic risk vector that does not require smart contract bugs in the affected downstream protocols.

The Stranded-Asset Problem: 20 Chains, No Reserve

The drained bridge held the master reserve backing wrapped rsETH on more than 20 L2 networks. With that reserve gone, holders of rsETH on Base, Arbitrum, Linea, Blast, Mantle, Scroll, and other chains now hold tokens with no clear path to redemption.

This creates a feedback loop: panic redemptions on L2s pressure the unaffected Ethereum-native rsETH supply, potentially forcing Kelp to unwind restaking positions through EigenLayer to honor withdrawals. EigenLayer unstaking typically involves a 7-day withdrawal queue, creating further delay and uncertainty.

The scale of the stranding problem is proportional to rsETH's multi-chain distribution. According to CoinDesk, the circulating supply stood at approximately 630,000 rsETH (tracked by CoinGecko), of which 116,500 — 18% — was drained. The remaining 82% of supply faces a confidence crisis: holders on L2s cannot verify whether the backing for their specific tokens still exists.

Bridge Exploits in Context

Cross-chain bridges remain the most exploited category of DeFi infrastructure. According to Chainlink Labs, over $2.8 billion has been stolen via bridge hacks since 2022, representing nearly 40% of all value stolen in Web3.

| Year | Notable Bridge Exploit | Loss | |---|---|---| | 2022 | Axie Infinity / Ronin Bridge | $600M | | 2022 | Wormhole | $320M | | 2023 | Multichain (CEO-linked keys) | $130M+ | | 2026 (Apr 1) | Drift Protocol (Solana) | $285M | | 2026 (Apr 18) | Kelp DAO (LayerZero) | $292M |

The Kelp exploit fits a recurring pattern: bridge security depends on the integrity of the messaging layer or validator set, and a single point of compromise can drain the entire reserve. Unlike smart contract exploits that can sometimes be bounded by pool-specific limits, bridge exploits expose the full reserve in a single transaction.

The 16 days between the Drift and Kelp exploits — both among the largest DeFi thefts ever recorded — have produced a combined $577 million in losses. In the same window, according to blockchain.news, at least 12 additional protocols were compromised, including CoW Swap, Zerion, Rhea Finance, and Silo Finance.

Key Takeaways

  • $292 million drained from Kelp DAO's LayerZero bridge in a single exploit — 2026's largest DeFi theft, surpassing Drift Protocol's $285 million loss 17 days earlier.
  • $236 million in bad debt created on Aave V3 after the attacker used unbacked rsETH as collateral to borrow WETH. Those positions are effectively unliquidatable.
  • Six protocols froze markets within hours: Aave (V3 + V4), SparkLend, Fluid, Lido Finance, Ethena, demonstrating how deeply rsETH was embedded as collateral across Ethereum's lending infrastructure.
  • 20+ L2 chains hold stranded rsETH whose backing reserve no longer exists, creating redemption uncertainty for holders outside Ethereum mainnet.
  • 46-minute response gap between the drain and contract freeze. Two follow-up attacks targeting an additional $200 million were blocked by the pause.
  • Aave's Umbrella slashing mechanism faces its first major test. aWETH stakers face automatic slashing, and WETH depositors may face a haircut on withdrawals.
  • $577 million in combined losses from Drift and Kelp exploits in 17 days, plus 12 additional protocol compromises in the same window.

Conclusion

The Kelp DAO exploit exposes two structural vulnerabilities in DeFi's current architecture. First, cross-chain bridges remain single points of failure that can drain entire reserves through messaging-layer compromises, regardless of the security of the protocols that accept the bridged tokens. Second, the composability of DeFi — where one token is accepted as collateral across multiple lending protocols — transforms a single exploit into a multi-protocol contagion event.

The $236 million in bad debt now sitting on Aave V3 was not caused by a flaw in Aave's contracts. It was caused by Aave's acceptance of rsETH as collateral — a token whose value depended on a bridge reserve that could be emptied in a single transaction. This dependency chain, from bridge reserve to collateral token to lending protocol to depositor haircut, illustrates the propagation risk inherent in DeFi's interconnected architecture.

Aave's Umbrella system is now undergoing its first significant real-world stress test. Whether it can absorb the deficit without broader market disruption will determine confidence in DeFi's risk management infrastructure for the remainder of 2026. The outcome has direct implications for how lending protocols evaluate liquid restaking tokens as collateral going forward.

Sources & References

  1. 2026's biggest crypto exploit: Kelp DAO hit for $292 million with wrapped ether stranded across 20 chains — CoinDesk, April 19, 2026
  2. KelpDAO rsETH Exploit Creates $290M Bad Debt on Aave — Startup Fortune, April 19, 2026
  3. Aave WETH Suppliers Urged to Withdraw After KelpDAO rsETH Exploit — Yahoo Finance / BeInCrypto, April 2026
  4. ZachXBT Flags $280M+ KelpDAO Exploit Hitting Ethereum DeFi Lending Markets — Bitcoin.com, April 18, 2026
  5. AAVE Price Crashes 10% as Aave-Backed KelpDAO Faces $280M Crypto Hack — CoinGape, April 2026
  6. Kelp DAO's rsETH token potentially exploited, $100M at risk — Crypto Briefing, April 18, 2026
  7. KelpDAO Exploiter Borrows $236M in WETH — Blockchain News, April 2026
  8. Kelp DAO's rsETH bridge apparently exploited for roughly $292 million in LayerZero-based attack — The Block, April 2026
  9. Cross-Chain Bridge Vulnerabilities — Chainlink Labs
  10. 12 DeFi Protocols Hit in Two-Week Hack Spree Following $280M Drift Exploit — Blockchain News, April 2026