📈 Get daily crypto insights that make you smarter about your money

Inside the KelpDAO Bridge Attack: How a Single Verification Node Unlocked $290m

On April 21, 2026, KelpDAO suffered one of the most devastating DeFi exploits in history when attackers drained approximately $290 million from the protocol’s liquid restaking token, rsETH. With Bitcoin trading at $79,827.91 and Ethereum at $2,346.40, this attack highlights critical vulnerabilities in omnichain bridge security that extend far beyond one protocol.

The Exploit Mechanics

The attack began with a fundamental design flaw in KelpDAO’s LayerZero omnichain fungible token (OFT) bridge configuration. Unlike multi-signature or timelock-protected systems, KelpDAO chose a single-verifier approach, creating a single point of failure that attackers ruthlessly exploited.

LayerZero bridges work by locking tokens on the source chain and minting equivalent tokens on destination chains. The verification process ensures only legitimate transfers occur. By compromising this single verification mechanism, attackers essentially tricked the entire system into believing fraudulent transfers were legitimate.

The preliminary investigation conducted by Galaxy Research identified the attackers as North Korea’s Lazarus Group, suggesting this was a state-sponsored operation rather than individual hackers. The sophistication of the attack patterns aligns with previous Lazarus operations targeting DeFi protocols.

Affected Systems

The immediate damage was staggering: attackers withdrew 116,500 rsETH from the Ethereum mainnet escrow — tokens that should never have been released. These stolen tokens were immediately deposited as collateral on major lending platforms primarily on Ethereum and Arbitrum blockchains.

Using the stolen rsETH as collateral, the attackers borrowed an estimated $236 million in wrapped Ethereum tokens (WETH and wstETH). This created massive exposure across the DeFi ecosystem, particularly on Aave where the protocol froze all rsETH, wrsETH, and WETH markets.

The fallout extended far beyond KelpDAO. With 112,204 rsETH (roughly 15% of post-exploit supply) becoming unbacked on the bridge adapter, and only 40,373 rsETH remaining as confirmed backing for the 152,577 rsETH outstanding on Layer 2 networks, systemic risk became apparent. Aave froze all rsETH-related markets across all deployments, and primary stablecoin markets reached 100% utilization, leaving zero liquidity for withdrawals.

The Mitigation Strategy

On Monday evening, the Arbitrum Security Council took emergency action to freeze 30,766 ETH held on Arbitrum and transfer it to an intermediary frozen wallet. This marked one of the few cases where a blockchain security council actively intervened to recover stolen funds, setting a significant precedent for future incidents.

Arbitrum’s intervention involved upgrading a bridge contract to enable fund recovery — a controversial move that demonstrated both the potential and risks of centralized security councils in decentralized systems. The decision prioritized victim recovery over strict adherence to immutable transaction principles.

Aave faced a difficult choice regarding its estimated $123.7 million in bad debt. The protocol could either implement uniform socialization of losses or isolate losses to L2 rsETH holders, each approach with different implications for protocol users and stakeholders. This represented one of the most significant governance challenges in DeFi history.

Lessons Learned

This exploit reveals several hard lessons about DeFi security architecture. The single-verifier configuration that enabled this attack demonstrates the dangers of over-optimizing for efficiency at the expense of security. LayerZero bridges, while innovative, require robust multi-signature implementations with timelocks.

The incident highlights the growing sophistication of state-sponsored attackers in the DeFi space. As protocols handle billions in assets, they must assume sophisticated adversaries rather than opportunistic hackers. Security needs to evolve from perimeter-based thinking to defense-in-depth strategies.

Perhaps most importantly, the $15 billion drop in total value locked across DeFi following the attack shows that systemic risk in one protocol can cascade through the entire ecosystem. This demands better coordination between protocols, clearer communication during crises, and potentially industry-wide insurance mechanisms.

User Action Required

If you held rsETH or interacted with KelpDAO before April 21, 2026, immediate action is essential. First, check your wallet for any unexplained rsETH transfers or unexpected collateral liquidations. Second, review your positions on Aave and other platforms affected by the protocol freezes. Third, monitor governance proposals regarding bad debt resolution and socialization mechanisms.

For protocols considering bridge implementations, this incident should serve as a red flag. Multi-signature verification, timelock mechanisms, and emergency shutdown capabilities are no longer optional features — they are necessities for any protocol handling significant user funds.

The KelpDAO exploit represents not just a technical failure, but a systemic warning about the evolving threat landscape in decentralized finance. As DeFi protocols mature, security must mature with them, moving beyond code audits to include real-world threat modeling and penetration testing by specialized ethical hacking groups.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always do your own research before making investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Inside the KelpDAO Bridge Attack: How a Single Verification Node Unlocked $290m”

  1. single verifier on a 550M protocol. KelpDAO chose convenience over security and Lazarus exploited it perfectly

  2. single verifier node for $290M in assets. LayerZero needs mandatory multi-DVN configs for anything over $10M TVL. this was preventable

    1. agree on mandatory multi-DVN. Aave freezing rsETH saved another 100M+ cascade. emergency response mattered more than the initial flaw here

    2. slasher_proof_ mandatory multi-DVN for anything over 10M is such an obvious standard. the fact this wasnt enforced in 2026 tells you DeFi security culture hasnt improved since 2022

  3. Ingrid Svanberg

    Aave freezing rsETH markets within hours was the only thing that prevented a bigger cascade. DeFi emergency response is getting faster

  4. attackers depositing stolen rsETH as collateral on Aave and borrowing 236M in WETH. using DeFi against itself

    1. using Aave as the exit liquidity was the clever part. deposit stolen rsETH, borrow WETH, dump. DeFi composability cuts both ways

      1. chaintan_ the Aave exit liquidity play was sophisticated. attacker understood DeFi composability better than most developers

      2. merkle_watch_

        chaintan_ the Aave exit liquidity play was the smartest part of the attack. deposit borrowed WETH, drain through multiple pools. they understood money legos better than the protocol devs

  5. Galaxy Research identifying Lazarus Group confirms state-sponsored. the 116.5K rsETH withdrawal from escrow should never have been possible with proper verification

  6. lazarus_pattern_

    Galaxy blaming Lazarus is convenient. attribution gives everyone closure but the attack worked because of bad config not because of state hackers

  7. 290M gone because one node signed off on everything. any protocol using a single verifier in 2026 deserves what they get honestly

    1. bridge_auditor_

      single verifier in 2026 is beyond negligent. LayerZero should enforce multi-DVN above certain TVL thresholds, not make it optional

    2. rekt_tabs a single verifier in 2026 is wild. LayerZero pushed the multi-DVN model specifically because of this attack and protocols still default to cheapest config

  8. LayerZero offering multi-DVN as optional is like selling a car where seatbelts are a premium add-on. enforce it above 10M TVL or accept this keeps happening

    1. single_verifier_rat

      Branco F. single verifier on a 290M protocol is criminal negligence. LayerZero offered multi-DVN and they chose not to use it to save on gas

  9. Lazarus using Aave as exit liquidity was the cleverest part. deposit stolen rsETH, borrow WETH, dump on the open market. DeFi composability working against itself

    1. Junko M. the Aave trick was identified within hours but nobody could front run it because the bridge had already minted the fake rsETH. speed kills in DeFi

  10. verifier_void_

    single verifier on a 290M TVL protocol and nobody on the team thought this was a problem until Lazarus walked out with everything

    1. verifier_void_ LayerZero literally offered multi-DVN configuration and KelpDAO opted out to save gas fees. 290 million lost to save maybe 5k in gas

  11. omnichain_rot_

    Lazarus using rsETH as Aave collateral to borrow 236M WETH was genuinely sophisticated. they understand DeFi composability better than most defi devs

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,464.00+0.6%ETH$1,903.71+2.0%SOL$73.71+0.0%BNB$594.10-0.8%XRP$1.06-1.0%ADA$0.1911-0.3%DOGE$0.0698-0.3%DOT$0.8399-2.2%AVAX$6.63-0.5%LINK$8.15+0.2%UNI$4.06+6.0%ATOM$1.35-1.7%LTC$45.14+0.0%ARB$0.0801-1.1%NEAR$1.70-1.2%FIL$0.7166+0.3%SUI$0.6880-0.4%BTC$64,464.00+0.6%ETH$1,903.71+2.0%SOL$73.71+0.0%BNB$594.10-0.8%XRP$1.06-1.0%ADA$0.1911-0.3%DOGE$0.0698-0.3%DOT$0.8399-2.2%AVAX$6.63-0.5%LINK$8.15+0.2%UNI$4.06+6.0%ATOM$1.35-1.7%LTC$45.14+0.0%ARB$0.0801-1.1%NEAR$1.70-1.2%FIL$0.7166+0.3%SUI$0.6880-0.4%
Scroll to Top