Skip to main content
Sign in

KelpDAO Bridge Exploit (April 2026)

avoid.net/kelpdao-bridge-exploit-april-20262/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]
anchored·H72JGF…UPJe

Summary

On April 18, 2026, attackers drained 116,500 rsETH (approximately $292–294 million) from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest DeFi exploit of 2026. The attack exploited a single-DVN (Decentralized Verifier Network) configuration by compromising RPC nodes and using a DDoS to force failover to poisoned infrastructure, tricking the bridge verifier into approving a phantom token release. The operation has been attributed with preliminary confidence to North Korea's Lazarus Group, specifically the TraderTraitor subunit, and triggered systemic contagion across at least 9 DeFi protocols and 20+ chains, including a major liquidity crisis on Aave.

Have evidence about KelpDAO Bridge Exploit (April 2026)?

Timeline(14 events)

2026-04-18

Attack executed at approximately 17:35 UTC. Attackers compromise KelpDAO's LayerZero bridge via poisoned RPC nodes, draining 116,500 rsETH (approximately $292 million). The DDoS against external nodes ran between approximately 10:20–11:40 a.m. Pacific Time to force failover to the attacker-controlled infrastructure.

CoinDesk, LayerZero Incident Statement

2026-04-18

Attacker deposits 89,567 stolen rsETH into Aave as collateral and borrows approximately $190.86 million in wrapped ETH before the asset is frozen.

CoinDesk, Aave Governance Forum

2026-04-18

KelpDAO's emergency pauser multisig freezes core contracts at 18:21 UTC, approximately 46 minutes after the exploit. Two follow-up drain attempts by the attacker at 18:26 and 18:28 UTC are blocked. Aave Guardian freezes rsETH markets at approximately 18:52 UTC.

CoinDesk

2026-04-18

KelpDAO publicly acknowledges the incident at approximately 20:10 UTC, roughly 3 hours after the initial drain.

CoinDesk

2026-04-20

Arbitrum Security Council freezes 30,766 ETH (approximately $71 million) attributable to the attacker on the Arbitrum network.

Unchained Crypto

2026-04-20

LayerZero releases a statement attributing the exploit to KelpDAO's 1-of-1 DVN configuration and linking the attack with preliminary confidence to North Korea's Lazarus Group / TraderTraitor subunit. KelpDAO disputes LayerZero's characterization and alleges LayerZero's default settings were responsible.

CoinDesk

2026-04-21

Chainalysis publishes on-chain analysis of the KelpDAO bridge exploit, consistent with TraderTraitor/Lazarus Group attribution.

Chainalysis

2026-04-23

Aave begins rallying DeFi ecosystem partners to contain fallout; DeFi United coalition begins forming.

CoinDesk

2026-04-30

U.S. District Court for the Southern District of New York issues a restraining order barring Arbitrum DAO from moving the 30,766 ETH frozen by the Arbitrum Security Council, following a claim filed by terrorism-judgment creditors of North Korea.

Unchained Crypto

2026-05-05

KelpDAO claims LayerZero had approved the single-DVN configuration it subsequently blamed for the exploit, escalating the public responsibility dispute.

CoinDesk

2026-05-10

LayerZero publishes detailed incident report and announces security changes, including a policy to refuse signing messages on any 1-of-1 DVN configuration and a full rebuild of the compromised cloud infrastructure.

The Market Periodical

2026-05-20

LayerZero publishes additional technical detail on the single-verifier architectural flaw at the root of the exploit.

CryptoTimes

2026-05-26

Aave and KelpDAO announce restoration of rsETH operations following the DeFi United recovery effort. KelpDAO confirms the final tranche of 20,373.72 rsETH has been delivered to the rsETH OFT adapter, completing the operational recovery phase.

CryptoTimes, AMBCrypto

2026-06-02

On-chain data cited by Arkham Intelligence indicates the attacker has laundered approximately $220 million of unfrozen stolen funds through THORChain, Wasabi, Tornado Cash, and Umbra, with only approximately $1.7 million remaining in the main attacker wallet.

CryptoTimes
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-sonnet-4-6

generated: 6/21/2026, 5:06:27 PM

last updated: 6/21/2026, 5:06:38 PM

avoid.net — verified advice for a post-truth world