KelpDAO Bridge Exploit (April 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·H72JGF…UPJeSummary
On April 18, 2026, approximately 116,500 rsETH tokens (valued at roughly $292 million) were fraudulently released from KelpDAO's LayerZero V2 bridge adapter via a forged cross-chain message — the largest single DeFi exploit of 2026. Security firms Mandiant, CrowdStrike, and Chainalysis, as well as LayerZero Labs, attributed the attack with high confidence to TraderTraitor (UNC4899), a North Korean state-linked threat actor operating under the Lazarus Group umbrella. The incident exposed systemic risk in off-chain verification infrastructure and triggered a protracted public dispute between KelpDAO and LayerZero over who bore responsibility for the single-verifier configuration that made the attack possible; LayerZero subsequently acknowledged it had made a mistake.
Connected Entities
19 entities · 60 linked investigations- KelpDAO Bridge Exploit (April 2026)→mentioned with→THORChain(65%)
- KelpDAO Bridge Exploit (April 2026)→mentioned with→Arbitrum(80%)
- KelpDAO Bridge Exploit (April 2026)→mentioned with→Mantle(65%)
- KelpDAO Bridge Exploit (April 2026)→mentioned with→Kelp(70%)
- KelpDAO Bridge Exploit (April 2026)→mentioned with→Ethena(60%)
- Ronin Bridge→mentioned with→Chainlink(70%)
- KelpDAO Bridge Exploit (April 2026)→mentioned with→Ethereum(80%)
- KelpDAO Bridge Exploit (April 2026)→mentioned with→Chainlink(60%)
- Ronin Bridge→mentioned with→Ethereum(80%)
- KelpDAO Bridge Exploit (April 2026)→mentioned with→WazirX(70%)
- + 88 more
Community submissions
“TRM Labs H1 2026 report confirms KelpDAO exploit ($292M, April 18, 2026) as the largest single H1 2026 crypto hack, attributed to North Korea-linked actors who compromised RPC nodes on the LayerZero bridge. This was an infrastructure breach, not a smart contract exploit. $292M represents ~30% of all H1 2026 crypto losses.”
— avoid-scout
“On-chain forensic evidence commingling funds from the KelpDAO exploit and the June 2026 Humanity Protocol hack, extending Lazarus Group attribution across both incidents.”
— avoid-scout
Timeline(10 events)
6 March 2026
According to LayerZero's incident report, a LayerZero Labs developer was socially engineered into cloning a malicious GitHub repository, which installed malware on their system and allowed the attacker to harvest session keys and access LayerZero's RPC cloud environment.
LayerZero Labs KelpDAO Incident Report18 April 2026
At approximately 17:35 UTC, attacker executes three transactions, submitting a forged LayerZero cross-chain message. KelpDAO's bridge escrow releases 116,500 rsETH (~$292 million) against a burn transaction that never occurred on the source chain. Stolen rsETH deposited into Aave V3 as collateral to borrow approximately $190–$236 million in WETH.
Hypernative / CoinDesk19 April 2026
Aave V3 freezes all rsETH and wrsETH reserves across deployments, sets LTV to zero. DeFi contagion triggers reported $8–10 billion in deposit outflows from Aave. Bloomberg reports incident as largest crypto hack of 2026.
CoinDesk / Bloomberg20 April 2026
LayerZero issues initial statement blaming KelpDAO's 1-of-1 DVN configuration and attributing the attack to North Korea's Lazarus Group. KelpDAO issues a counter-statement claiming LayerZero's default settings caused the disaster.
CoinDesk23 April 2026
Aave rallies DeFi partners — including Mantle, Lido DAO, EtherFi, and LayerZero — to form the DeFi United coalition to restore rsETH backing and cover Aave's bad debt.
CoinDesk28 April 2026
DeFi United coalition releases detailed technical recovery proposal for restoring rsETH backing.
CoinDesk / The Block5 May 2026
KelpDAO publishes detailed memo asserting that LayerZero personnel directly approved the single-verifier configuration across approximately eight integration meetings over roughly two and a half years. KelpDAO announces migration of rsETH bridging from LayerZero to Chainlink CCIP.
CoinDesk / Unchained Crypto9 May 2026
LayerZero reverses course, publicly admitting: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions. We own that.' LayerZero announces it will no longer service 1-of-1 DVN configurations and will migrate all defaults to a minimum of 3-of-3.
CoinDesk18 May 2026
LayerZero Labs publishes its full public incident report detailing the attack timeline, social engineering vector, RPC compromise methodology, and attribution to DPRK TraderTraitor unit.
LayerZero Labs Incident Report25 May 2026
KelpDAO and Aave jointly announce that rsETH has been fully restored. The final tranche of 20,373.7 rsETH is transferred to the LayerZero lockbox contract, completing recovery approximately five weeks after the exploit. All Aave markets and rsETH operations confirmed as functioning normally.
CryptoTimes / NFT PlazasDecision Log
- hash: CaE5WDFyaUTXMuwhVDkdebxkab3g3hVcUy8PGJ3bmhc5
- hash: 5QTH6yM77Kzw8bAaEUQmCbbRkacBEvShaQtYTJXkWfnR
- hash: J8wnmttB8ey1drSSEFUbpiL1vw76ndUh5ZM1zn3zbzCq
This investigation is cryptographically anchored to the Solana blockchain (3 events). 31 of 33 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/21/2026, 5:06:27 PM
last updated: 9/21/2026, 12:10:57 AM
3 viewsavoid.net — verified advice for a post-truth world