The $292 million Kelp DAO bridge exploit on April 18 triggered the largest coordinated recovery operation in decentralized finance history. Four weeks later, on May 15, rsETH withdrawals reopened across five networks after DeFi United — an ad hoc coalition of protocols, foundations, and individua...
"The issue was beyond Aave. It was about restoring the whole state of DeFi, avoiding contagion and ensuring that the whole ecosystem overcomes this incident." — Stani Kulechov, Founder, Aave
The $292 million Kelp DAO bridge exploit on April 18 triggered the largest coordinated recovery operation in decentralized finance history. Four weeks later, on May 15, rsETH withdrawals reopened across five networks after DeFi United — an ad hoc coalition of protocols, foundations, and individuals — raised over $311 million in ETH commitments to restore token backing. The episode exposed structural risk in liquid restaking tokens used as lending collateral and prompted a 72,000% surge in Ethereum's validator exit queue.
The crisis arc — from exploit to contagion to bailout to recovery — lasted 27 days. It produced $190 million in bad debt on Aave, erased $6.6 billion in TVL from the lending protocol, and forced $5.4 billion in sector-wide withdrawals. It also produced DeFi's first mutual-aid framework: a template for industry self-rescue that Kulechov has proposed making permanent infrastructure.
At 17:35 UTC on Saturday, April 18, 2026, an attacker forged a cross-chain message through Kelp DAO's LayerZero-powered bridge. The fabricated message tricked the bridge contract's lzReceive function into releasing approximately 116,500 rsETH — roughly 18% of the token's 630,000 circulating supply — to an attacker-controlled wallet.
The exploit targeted Kelp DAO's single-verifier bridge configuration. According to post-mortem analysis by Chainalysis, the attack was an RPC poisoning operation attributed with preliminary confidence to North Korea's Lazarus Group.
Key figures:
| Metric | Value | |--------|-------| | Total drained | 116,500 rsETH (~$292M) | | Share of circulating supply | ~18% | | Attack vector | Forged LayerZero cross-chain message | | Attribution | Lazarus Group (Chainalysis) | | Chains affected | 20+ (rsETH stranded across multichain deployment) |
The attacker subsequently deposited the minted unbacked rsETH as collateral on Aave V3 across Ethereum and Arbitrum, borrowing approximately $190 million in ETH and WETH before withdrawal pauses were enacted.
The exploit exposed a systemic vulnerability in DeFi's collateral stack. Liquid restaking tokens (LRTs) had been whitelisted across major lending protocols because they carried yield and represented a growing share of Ethereum's locked value. Risk models priced them assuming peg stability under normal conditions. None priced a scenario where the collateral backing goes to zero because a bridge on a chain the lender does not directly interface with gets exploited on a weekend.
The immediate fallout:
The Aave Umbrella reserve mechanism, designed to absorb losses through stkAAVE holder slashing, faced questions about its capacity to cover the full deficit. This raised the prospect that governance token holders could directly absorb losses — a scenario previously theoretical.
Ethereum's validator exit queue swelled to 433,158 ETH by May 3, climbing approximately 72,000% in two weeks. The surge tracked directly to April's $625 million in aggregate DeFi losses — the worst month for crypto exploits on record across 30 separate incidents.
Current Ethereum staking metrics as of mid-May 2026:
| Metric | Value | |--------|-------| | Active validators | ~1,100,000 | | Total ETH staked | 35.86 million (28.9% of supply) | | Entry queue | 3.6 million ETH (62-day wait) | | Exit queue peak (May 3) | 433,158 ETH (7-day wait) | | Annual staking yield | ~2.9–3.3% |
The entry queue remains roughly 7x the size of the exit queue, indicating that capital rotation rather than net de-staking characterizes the current dynamic. Validators finalized block 25,000,000 on May 1, a network milestone that occurred mid-crisis.
Within days of the exploit, Aave spearheaded the formation of DeFi United — a coalition that pulled together capital commitments from across the Ethereum ecosystem to restore rsETH backing and cover Aave's bad debt.
Total commitments exceeded $311 million. Major contributors:
| Contributor | Commitment | |-------------|-----------| | Consensys / Joseph Lubin | 30,000 ETH | | Mantle (credit facility loan) | 30,000 ETH | | Arbitrum DAO (frozen attacker funds) | 30,766 ETH | | Aave DAO (treasury allocation proposal) | Up to 250,000 ETH | | Stani Kulechov (personal) | 5,000 ETH | | EtherFi (under discussion) | 5,000 ETH | | Lido | Up to 2,500 stETH | | Compound | Up to 3,000 ETH |
The Arbitrum contribution came from frozen attacker funds. On April 21, the Arbitrum Security Council acted with a 9-of-12 supermajority to freeze 30,766 ETH ($71 million) that the attacker had moved to an Arbitrum One address. A temperature check vote opening May 1 drew 16.9 million ARB in support within the first hour with no opposition.
According to CoinDesk reporting on April 26, Aave had raised approximately $160 million of the $200 million needed to cover exploit-related damage through the DeFi United initiative by that date.
On May 14–15, Kelp DAO and Aave announced the first user-facing recovery milestone:
The protocol confirmed rsETH remains fully backed across mainnet and all Layer 2 networks following the refill operation. Kelp DAO also confirmed its planned migration from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP) remains on track — a decision that preceded the exploit but gained urgency following it.
As of May 17, rsETH trades at approximately $2,385–$2,420, according to CoinGecko and CoinMarketCap data.
The Kelp DAO crisis crystallized several structural risks in the restaking ecosystem:
1. Cross-chain bridge as single point of failure. Kelp's single-verifier bridge configuration allowed a forged message to drain 18% of circulating supply. The protocol's multi-chain architecture — rsETH deployed across 20+ chains — amplified the blast radius.
2. LRT collateral assumptions in lending. Risk models for whitelisting restaking tokens as collateral did not account for bridge-originated supply shocks. The gap between the perceived risk (low — it's staked ETH) and the actual risk (high — bridge-dependent backing) was the core miscalculation.
3. Entry queue vs. exit queue asymmetry. With 3.6 million ETH waiting to enter staking against 433,158 ETH in the exit queue, the system absorbed the shock without a net staking decline. However, the 72,000% exit queue surge demonstrates how quickly confidence-driven withdrawals can create processing bottlenecks.
4. DeFi self-insurance gap. The Aave Umbrella reserve was insufficient to cover losses alone. DeFi United functioned as an ad hoc mutual-aid fund — effective but improvised. Kulechov has proposed formalizing this into permanent crisis infrastructure.
5. EigenLayer concentration. EigenLayer holds approximately 94% of the restaking market with $19 billion in TVL across 4.6 million ETH. The Kelp exploit did not directly compromise EigenLayer's smart contracts, but the downstream contagion demonstrated how failures in the LRT layer propagate through the broader restaking stack.
The Kelp DAO exploit and subsequent recovery represent a stress test for DeFi's interconnected restaking infrastructure. The system did not collapse — but it required an unprecedented, improvised mutual-aid operation to remain solvent. The 27-day recovery window, during which $292 million in user funds were frozen across 20 chains, is incompatible with the "always-on" promise of decentralized finance.
The DeFi United model — where competitors coordinate capital to prevent systemic failure — resembles traditional finance's lender-of-last-resort function, executed without a central bank. Whether this becomes formalized infrastructure or remains a one-time event will determine how the market prices restaking risk going forward.
EigenLayer's restaking market ($19 billion TVL) survived without direct smart contract compromise. The vulnerability was downstream: in bridge implementations, in collateral assumptions, and in the assumption that liquid restaking tokens carry the same risk profile as the underlying staked ETH. That assumption is now permanently revised.