Trending

    Kelp DAO suffers $292 million exploit impacting Aave protocol

    High7 articles covering this·6 news sources·Updated 3 hours ago·World
    Share:

    Here's what it means for you.

    If you’re involved in DeFi or hold assets on lending platforms, this exploit could impact your liquidity and borrowing options.

    Why it matters

    This incident underscores vulnerabilities in cross-chain protocols, potentially shaking confidence in decentralized finance.

    What happened (in 30 seconds)

    • Kelp DAO suffered a $292 million exploit on April 18, 2026, through its LayerZero bridge, minting unbacked rsETH tokens.
    • Aave faced approximately $196 million in bad debt after these tokens were used as collateral to borrow real ETH, triggering liquidity crises.
    • DeFi United formed to address the fallout, pledging over $160 million to cover the shortfall without treasury emissions.

    The context you actually need

    • Kelp DAO operates as a liquid restaking protocol, allowing users to earn yields while maintaining liquidity, which is crucial in the current DeFi landscape.
    • LayerZero's single-verifier setup was exploited, despite prior warnings, highlighting risks in cross-chain configurations as protocols expand across multiple networks.
    • Aave's liquidity crisis led to $18 billion in outflows, reducing its total value locked (TVL) from $48.5 billion to $30.7 billion, indicating a significant loss of trust in the platform.

    What's really happening

    On April 18, 2026, at 17:35 UTC, attackers exploited vulnerabilities in Kelp DAO's LayerZero bridge by forging a cross-chain message. This action led to the minting of 116,500 unbacked rsETH tokens, valued at $292 million. These tokens were then deposited on Aave V3 as collateral to borrow approximately $196 million in ETH. The exploit occurred amid a booming restaking sector, where protocols like Kelp were rapidly expanding their multi-chain deployments across over 20 networks, including Arbitrum, Base, and Mantle.

    Kelp DAO paused its core contracts shortly after the exploit was detected at 18:21 UTC. In response, Aave and other protocols froze rsETH markets within hours, averting immediate liquidations but triggering a massive liquidity crisis. The incident resulted in an estimated $18 billion in outflows from Aave, significantly reducing its TVL. Incident reports from Aave Labs and LlamaRisk estimated the bad debt at between $124 million and $230 million, indicating the scale of the financial impact.

    In the aftermath, Arbitrum's Security Council took action by freezing $71 million in linked ETH to mitigate further losses. By April 23, DeFi United was formed under Aave leadership to coordinate recovery efforts. This coalition included significant pledges from various protocols, such as Aave's 25,000 ETH (approximately $58 million), Mantle's 30,000 ETH loan, and Lido's 2,500 stETH (valued at $5.8 million), totaling over $160 million in community contributions by April 26.

    The exploit has drawn attention to the vulnerabilities inherent in cross-chain bridges, particularly those relying on single-verifier setups. LayerZero attributed the attack to North Korea's Lazarus Group, suggesting that sophisticated actors are increasingly targeting DeFi protocols. The incident has raised questions about the security measures in place across the DeFi landscape and the potential for future exploits.

    Who feels it first (and how)

    • DeFi Users: Those who use Aave and similar platforms may face reduced liquidity and borrowing options.
    • Investors: Holders of AAVE tokens experienced an initial decline of 18-20% in value, impacting their portfolios.
    • Developers: Teams working on cross-chain protocols may need to reassess security measures and configurations to prevent similar exploits.
    • Regulators: Increased scrutiny on DeFi protocols may arise, leading to potential regulatory changes affecting operations.

    What to watch next

    • Recovery Fund Progress: Monitor how effectively DeFi United manages the recovery fund and whether it can stabilize Aave's liquidity. This will indicate the resilience of community-driven recovery efforts.
    • Security Enhancements: Watch for announcements regarding security upgrades across cross-chain protocols, particularly those using LayerZero technology. This will reveal how the industry adapts to vulnerabilities.
    • Market Reactions: Observe the price movements of AAVE and other DeFi tokens in the wake of this exploit. Significant fluctuations could signal ongoing market instability or recovery.
    Known:

    Kelp DAO's exploit resulted in significant bad debt for Aave, impacting its liquidity.

    Likely:

    Increased scrutiny and potential regulatory changes for DeFi protocols as a result of this incident.

    Unclear:

    The long-term effects on user trust and participation in DeFi platforms following this exploit.

    Insights by A47 Intelligence

    7 Articles
    Crypto Briefing

    Kelp DAO exploit leaves AAVE with $196M bad debt, Ethereum market steady

    The Kelp DAO has suffered a significant exploit, resulting in a loss of approximately $292 million, which has left AAVE with $196 million in bad debt. This incident has raised concerns about the security of decentralized finance (DeFi) platforms and ...

    Bitcoinist

    Kelp DAO Hack: Aave DAO Proposes To Contribute 25,000 ETH To Recovery Efforts

    Aave DAO has proposed to allocate 25,000 ETH from its treasury to assist in recovery efforts following a significant exploit of Kelp DAO, which resulted in the loss of approximately $292 million. This initiative is part of a broader effort termed 'De...

    20 hours ago
    Read Full Article
    Crypto News

    Kelp’s $292M exploit sparks 2008-style DeFi risk debate

    Kelp DAO has experienced a significant security breach, resulting in the loss of approximately $292 million due to an exploit involving its LayerZero-powered bridge and the rsETH token. This incident has triggered widespread withdrawals and market pa...

    Crypto News

    Aave leads $101M DeFi rescue effort to restore rsETH backing after Kelp hack

    Aave has spearheaded a $101 million decentralized finance (DeFi) initiative to stabilize rsETH following a significant exploit of Kelp DAO, which resulted in a loss of approximately $292 million. This coordinated effort, termed “DeFi United,” aims to...

    Bitcoin.com

    Cryptoquant: KelpDAO Hack ‘Contagion’ Triggers Worst DeFi Liquidity Crunch Since 2024

    The KelpDAO hack has triggered a severe liquidity crisis in decentralized finance (DeFi), marking the worst liquidity crunch since 2024. The exploit resulted in a staggering loss of approximately $292 million, leading to significant financial repercu...

    CoinDesk

    Aave rallies DeFi partners to contain fallout from $292 million KelpDAO hack

    Aave is mobilizing its DeFi partners, including Lido and EtherFi, to address the fallout from a significant hack of KelpDAO that resulted in a loss of approximately $292 million. This incident has raised alarms across the cryptocurrency sector, promp...

    NewsBTC

    DeFi Just Lost $15 Billion in Three Days. Something Deeper Than a Hack Is Behind It

    The decentralized finance (DeFi) sector has faced a severe crisis, losing approximately $15 billion in just three days due to a significant exploit at Kelp DAO. The incident began on April 19 when an attacker exploited a flaw in the protocol's collat...