An attacker drained 116,500 rsETH — approximately $292 million — from Kelp DAO's LayerZero-powered cross-chain bridge on April 18, 2026, at 17:35 UTC. The exploit, now the largest DeFi security breach of 2026, surpassed the Drift Protocol hack by roughly $7 million and created a cascading failure...
"Wish I had better news but looks like WETH on Aave is fucked. Withdraw if you can but likely too late." — 0xQuit, Solidity Developer and Auditor
An attacker drained 116,500 rsETH — approximately $292 million — from Kelp DAO's LayerZero-powered cross-chain bridge on April 18, 2026, at 17:35 UTC. The exploit, now the largest DeFi security breach of 2026, surpassed the Drift Protocol hack by roughly $7 million and created a cascading failure across more than 20 blockchain networks where wrapped rsETH circulates.
The attacker spoofed a cross-chain message through LayerZero's messaging layer, tricking the bridge into releasing the tokens to an attacker-controlled address funded via Tornado Cash. The stolen rsETH was then deposited as collateral on Aave V3, where the attacker borrowed a substantial volume of Wrapped Ether (WETH). Because the drained rsETH lost its backing the moment it left the bridge, the collateral posted on Aave is effectively worthless — creating unliquidatable bad debt on the protocol's balance sheet.
Kelp's emergency pauser multisig froze core contracts 46 minutes after the drain. Two follow-up exploit attempts at 18:26 and 18:28 UTC, each targeting an additional 40,000 rsETH (~$100 million), reverted against the frozen contracts. Aave, SparkLend, and Fluid froze their rsETH markets within hours.
At 17:35 UTC on Saturday, April 18, an attacker executed a single transaction that drained 116,500 rsETH from Kelp DAO's bridge contract. The stolen amount represents roughly 18% of rsETH's 630,000-token circulating supply.
The technical vector exploited LayerZero's Omnichain Fungible Token (OFT) standard, which Kelp uses to move rsETH across networks. The attacker crafted a spoofed cross-chain message that LayerZero's messaging layer interpreted as a valid instruction arriving from another network. This triggered the bridge to release its rsETH reserves to the attacker's address.
The attacker funded the exploit wallets through Tornado Cash. On-chain investigator ZachXBT flagged the active exploit at approximately 19:44 UTC, by which time the 116,500 rsETH had already been siphoned.
Kelp's emergency pauser multisig activated 46 minutes after the initial drain, freezing the protocol's core contracts at 18:21 UTC. The delay proved consequential: two additional exploit attempts arrived at 18:26 and 18:28 UTC, each carrying the same LayerZero packet structure and attempting to extract another 40,000 rsETH (~$100 million). Both reverted against the frozen contracts. Had the pauser acted slower, total losses could have exceeded $390 million.
Kelp DAO has not disclosed precisely how the exploit bypassed the bridge's validation logic. No post-mortem had been published as of press time.
The $292 million loss makes the Kelp DAO exploit the largest DeFi hack of 2026, overtaking the Drift Protocol exploit ($285 million, April 1) by roughly $7 million. It is the second major DeFi exploit in 18 days.
Kelp DAO is the second-largest liquid restaking protocol in the EigenLayer ecosystem. Before the exploit, the protocol held over $2 billion in total value locked (TVL), trailing only EtherFi ($5.6 billion). The broader EigenLayer ecosystem held approximately $18 billion in restaked ETH across 1,900 active operators as of March 2026.
Kelp (which rebranded from its original identity to Kernel DAO in late 2024) had secured $9 million in funding at a $90 million valuation. The KERNEL token, which carried a roughly $31 million market cap against $2 billion+ in TVL, was already flagged by analysts as undervalued relative to deposits. The exploit has inverted that thesis: deposits are now the liability, not the asset.
AAVE fell approximately 8-10% in the hours following the exploit, trading near $92.70.
The exploit's structural damage extends far beyond the $292 million headline figure. Kelp DAO deployed rsETH across more than 20 networks — including Base, Arbitrum, Linea, Blast, Mantle, and Scroll — using LayerZero's OFT standard to handle cross-chain movement. All wrapped rsETH on these layer-2 networks was backed by a single reserve pool held in the bridge contract on Ethereum mainnet.
That reserve is now drained.
Holders of rsETH on any non-Ethereum deployment face a direct question: does their token have anything backing it? The answer, pending recovery or restitution, is no. This creates a feedback loop. Holders on L2s attempting to exit must bridge back to Ethereum to redeem, but the bridge is frozen. Those who hold rsETH in DeFi positions on L2s — as collateral, in liquidity pools, or in yield vaults — face the same impairment without a clear exit path.
The incident demonstrates a systemic risk in the "hub-and-spoke" bridge model: a single Ethereum-side reserve backs wrapped tokens across an arbitrary number of chains. The attack surface is concentrated at the bridge. If the bridge fails, every chain downstream fails simultaneously.
The attacker did not simply steal the rsETH. In a second-stage operation, the stolen tokens were deposited as collateral on Aave V3, and a substantial amount of WETH was borrowed against them.
Under normal conditions, rsETH maintains its value as a claim on staked ETH deposited through EigenLayer. If a borrower's collateral falls below the liquidation threshold, Aave's liquidation engine sells the collateral to repay the debt. But the stolen rsETH is no longer backed by real underlying assets — the bridge reserve that previously backed it has been drained. The collateral is, in economic terms, worthless.
This makes the positions unliquidatable through normal mechanisms. No rational liquidator will buy unbacked rsETH to close out the debt. The result is bad debt: Aave holds WETH obligations it cannot recover through its standard liquidation process.
Aave's response pointed to its Umbrella backstop system. Under this mechanism, aWETH stakers face automatic slashing to cover the deficit — meaning Aave's own depositors absorb the loss. Aave founder Stani Kulechov stated that Aave's own contracts were not compromised and the exploit was entirely external.
The distinction matters legally but is cold comfort to WETH suppliers. As 0xQuit, a Solidity developer and auditor, warned: the WETH pool on Aave carries impaired collateral, and suppliers who cannot withdraw before the bad debt is socialized will bear the cost.
Kelp DAO: Activated emergency pauser multisig at 18:21 UTC. Core contracts frozen. No official post-mortem or public statement issued as of April 19. The team has not disclosed recovery prospects or plans for affected L2 rsETH holders.
Aave: Froze rsETH markets on both V3 and V4 within hours. Kulechov confirmed contracts were not exploited. Umbrella backstop system to handle bad debt through aWETH staker slashing. Governance process underway to formalize the response.
SparkLend: Froze rsETH markets.
Fluid: Froze rsETH markets.
Lido Finance: Paused further deposits into its earnETH product, which carries rsETH exposure. Clarified that stETH and wstETH are unaffected and the core Lido staking protocol has no involvement.
LayerZero: No public statement identified as of press time regarding how the cross-chain messaging validation was bypassed.
Cross-chain bridges remain DeFi's most exploited infrastructure. The Kelp DAO hack follows a well-documented pattern:
The Kelp exploit adds a new entry to this list with a specific wrinkle: the OFT standard's hub-and-spoke architecture concentrated all cross-chain risk at a single bridge contract. LayerZero's design philosophy allows each application to select its own security properties — including its own oracle and relayer configuration. This configurability, intended as a feature, means security outcomes depend on each application's implementation choices rather than protocol-level guarantees.
LayerZero has historically denied that its architecture contains systemic vulnerabilities. In 2023, the company responded to claims by Nomad's James Prestwich about a potential "backdoor" by stating that each application controls its own security parameters. The Kelp exploit tests whether that delegation of responsibility provides sufficient protection in practice.
The DeFi security environment has deteriorated measurably in April 2026. According to Blockchain News, at least 12 protocols were attacked in the two-week period following the Drift exploit on April 1. Combined losses including Drift, Grinex ($13.7 million), Rhea Finance ($7.6 million), and now Kelp DAO exceed $600 million in 18 days.
The Kelp DAO exploit exposes a structural vulnerability that the liquid restaking sector has accumulated: billions of dollars of cross-chain value secured by bridge contracts whose failure can simultaneously impair tokens across 20 or more networks. The attack was not a smart contract bug in the traditional sense — it was a messaging-layer compromise that tricked infrastructure into doing exactly what it was designed to do, just for the wrong party.
The economic damage extends beyond the $292 million headline. Aave carries bad debt. L2 rsETH holders are stranded. The Umbrella backstop socializes losses across Aave's WETH depositor base. And the liquid restaking sector — which holds $18 billion in restaked ETH through EigenLayer alone — now faces renewed scrutiny over the concentration of bridge risk.
Two exploits exceeding $285 million in 18 days is not a coincidence. It is a signal that the DeFi security posture has not scaled with the capital it secures.