At 17:35 UTC on Saturday, April 18, 2026, a single transaction changed hands on the Ethereum blockchain. What that transaction did, in 46 minutes, was drain $292 million from a DeFi protocol called KelpDAO by forging a verification message, depositing the stolen tokens as collateral on the largest lending protocol in DeFi, and borrowing hundreds of millions in real wrapped ether against thin air. By Sunday, $13.21 billion in total value had left DeFi. Aave, which did nothing wrong and whose smart contracts were not compromised, lost $8.45 billion in deposits in 48 hours and is carrying somewhere between $177 million and $236 million in bad debt that may have no clean resolution. This is the biggest DeFi story of 2026. This blog explains exactly what happened, why it happened, and what it reveals about the structural vulnerabilities that allowed a single misconfigured setting to cascade into a $13 billion market event.
By CryptoAcademy Team | Published: 2026-04-20 | 18 min read time read | Category: Educational
Before the exploit, KelpDAO was one of the larger protocols in the rapidly growing liquid restaking market. Understanding what it does is essential to understanding how the attack worked.
Ethereum holders who stake ETH to help secure the Ethereum network earn staking rewards. Liquid staking protocols like Lido take this a step further: you deposit ETH, receive a liquid token (stETH in Lido's case) that represents your staked position, and can use that liquid token in DeFi while your ETH continues earning staking rewards.
KelpDAO operates at a third layer called restaking, built on the EigenLayer protocol. Users deposit already-staked ETH into KelpDAO, which then delegates those assets to EigenLayer operators who secure additional networks and services. In return, users receive rsETH, KelpDAO's liquid restaking token. rsETH represents a claim on the restaked ETH plus all associated yield: Ethereum staking rewards, EigenLayer rewards, and KelpDAO's own incentives.
By April 2026, rsETH had crossed $1 billion in total value locked and had been integrated as collateral across most of the major lending markets in DeFi. Aave, the largest DeFi lender, accepted rsETH as collateral because it was considered ETH-correlated: backed one-to-one by real restaked ether.
rsETH lives natively on Ethereum, but its utility depends on being everywhere. Users on Arbitrum, Base, Mantle, Unichain, Linea, Scroll, and more than a dozen other networks need to be able to hold and use rsETH. KelpDAO used LayerZero's cross-chain messaging system to move rsETH between networks. When you want to use rsETH on Arbitrum, a message goes through LayerZero's bridge infrastructure, the bridge on Arbitrum releases or mints an equivalent amount of rsETH, and your position moves.
The bridge that held the rsETH reserves backing all those cross-chain versions was the target. And the security configuration protecting that bridge was a single point of failure.
---
The attack was sophisticated, patient, and devastating in its efficiency.
The attacker funded their wallet through Tornado Cash approximately 10 hours before the exploit, a classic operational security move that breaks the on-chain trail between the attacker and any exchange or wallet that might be identifiable.
At exactly 17:35 UTC on April 18, 2026, in Ethereum block 24,908,285, a transaction called the "lzReceive" function on LayerZero's EndpointV2 contract. This is the function that processes incoming cross-chain messages and, if they pass verification, instructs the bridge to release funds. The message told the bridge that a valid instruction had arrived from another network, authorising the release of 116,500 rsETH to an attacker-controlled address.
The message was forged. No ETH had been deposited on the other side. No legitimate instruction had been sent. The 116,500 rsETH released by the bridge represented approximately 18% of rsETH's entire circulating supply, conjured from nothing.
KelpDAO's emergency multisig froze the protocol's core contracts 46 minutes later at 18:21 UTC. Two follow-up attempts at 18:26 and 18:28 UTC, each carrying similar LayerZero packets attempting another 40,000 rsETH drain worth roughly $100 million, both reverted against the now-paused bridge.
But the attacker did not need those follow-up attempts to work. They already had $292 million in rsETH and had deployed it with precision.
Rather than immediately trying to sell 18% of rsETH's supply, which would have instantly crashed the price and potentially recovered only a fraction of the nominal value, the attacker did something more elegant and more damaging. They deposited the stolen rsETH into Aave V3 as collateral and borrowed real wrapped ether against it. They then repeated the trick on Aave V4. By the time Kelp's emergency pause was active, the real WETH was already in the attacker's control, and the stolen rsETH was sitting locked in Aave as collateral for loans that would never be repaid.
The attacker walked away with approximately $266 million in real ETH. The unbacked rsETH stayed in Aave's lending pool, with no legitimate collateral behind it, and nobody available to repay the loans or redeem the tokens for anything.
---
LayerZero's cross-chain messaging system works through Decentralised Verifier Networks (DVNs). A DVN is an independent entity responsible for attesting that a cross-chain message is legitimate before the destination chain acts on it. LayerZero's architecture allows protocols to choose how many DVNs must agree before a message is accepted.
The security philosophy is straightforward: if multiple independent verifiers must all confirm a message, a single compromised verifier cannot authorise fraudulent transactions. A 2-of-3 or 3-of-5 configuration requires attackers to simultaneously compromise multiple unrelated verification entities, which is exponentially harder.
KelpDAO's rsETH bridge was configured with a 1-of-1 DVN setup. A single verifier: LayerZero Labs itself. One attestation was all that was needed to release any amount of rsETH from the bridge.
LayerZero's public integration checklist and direct communications to KelpDAO had recommended a multi-verifier setup with redundancy. That recommendation was not implemented.
The attack exploited this configuration in a specific and sophisticated way. The attackers obtained a list of RPC nodes used by LayerZero Labs' verifier. RPC (Remote Procedure Call) nodes are the servers that let software read and write data on a blockchain. LayerZero's verifier relied on a mix of internal and external RPC nodes for redundancy.
The attackers compromised two of those RPC nodes, replacing their software with malicious versions designed to report that a fraudulent transaction had occurred on the source chain, while continuing to report accurate data to every other system querying those same nodes. The selective lying was engineered to keep the attack invisible to LayerZero's own monitoring infrastructure. To complete the operation, the attackers simultaneously launched a distributed denial-of-service attack against the uninfected RPC nodes, forcing LayerZero's verifier to fail over to the poisoned endpoints.
With the poisoned RPC nodes feeding false data to the only DVN standing between the attacker and $292 million, the bridge had no independent source of truth to consult. It accepted the forged message as legitimate.
The attack vector was a forged LayerZero packet. KelpDAO's rsETH OFT adapter was configured with a one-of-one DVN threshold, meaning a single forged verifier attestation was sufficient to authorise the release of funds.
LayerZero confirmed there is no core protocol bug. The bridge code functioned exactly as designed. What failed was the deployment configuration, a choice about how many independent verifiers to require. And that choice sat outside the scope of the standard smart contract audits that KelpDAO had undergone.
> Real-world example:
> "Had rsETH sitting in Aave as collateral for a modest borrowing position. When the exploit news broke, logged in to check and saw the rsETH market had been frozen. Could not deposit more collateral. Could not exit the position cleanly. The protocol had not been hacked, the funds were technically fine, but the market freeze created a situation where normal risk management was temporarily impossible. Even being three steps removed from the exploited bridge, the freeze created real operational problems. That is what contagion means in DeFi: it is not about being directly affected, it is about losing access to the liquidity management tools you depend on."
---
The attacker's decision to deposit stolen rsETH into Aave rather than selling it immediately was the move that transformed a large hack into a systemic crisis.
Aave is the largest lending protocol in DeFi, with total value locked of approximately $26.4 billion on April 18. It accepted rsETH as collateral because rsETH was considered ETH-correlated, backed by real restaked ether. When the attacker borrowed $266 million in real wrapped ether against unbacked rsETH, Aave suddenly held a large collateral position that had no legitimate backing and no clear path to redemption.
Aave froze its rsETH markets on V3 and V4 within hours of the exploit becoming known. SparkLend, Fluid, and Upshift paused or froze their rsETH markets. Compound and Euler also took protective measures. The freezes were the right defensive move. But they created an immediate practical problem: everyone who had legitimately deposited WETH into Aave's lending pool found that their deposits were locked. WETH pool utilisation hit 100%, meaning WETH depositors could no longer withdraw.
This triggered a bank run on Aave more broadly. Users who had nothing to do with rsETH began withdrawing their deposits, not because Aave had been hacked but because they could see what was happening and wanted to be out before conditions worsened. Rational individual responses to perceived risk produced collective panic that amplified the damage.
Aave's TVL plunged from $26.4 billion to approximately $17.9 billion over 48 hours, a loss of $8.45 billion in deposits. The AAVE token fell approximately 16% to 18%.
Across all of DeFi, the total value locked declined by $13.21 billion in two days, falling from approximately $99.5 billion to $86.3 billion. Multiple lending and yield protocols recorded double-digit percentage TVL declines.
Aave is now carrying between $177 million and $236 million in bad debt from the rsETH collateral positions. The Umbrella insurance fund, Aave's backstop for exactly these situations, holds approximately $50 million. That leaves a gap of roughly $127 million to $186 million that has no clean resolution. The borrow positions are effectively unliquidatable because the rsETH collateral cannot be redeemed at Kelp and will not trade near peg once the full scale of unbacked supply is understood.
---
LayerZero attributed the attack with preliminary confidence to TraderTraitor, a sophisticated cyber-operations unit that is a subsidiary of North Korea's Lazarus Group.
This attribution, if confirmed, makes the KelpDAO exploit the second major DeFi heist linked to North Korean state actors in a single month. The Drift Protocol exploit on April 1, 2026, which drained approximately $285 million through a social engineering attack on governance signers, has also been attributed to the same group with medium confidence by Mandiant and Elliptic.
Two separate DeFi protocols, $575 million drained in 18 days, through two structurally different attack vectors. Lazarus is adapting its playbook faster than DeFi protocols are hardening their defences.
The pattern of North Korean state-sponsored attacks on DeFi has been documented since at least 2021. What makes the KelpDAO attack notable is the level of technical sophistication: gaining access to RPC node infrastructure, replacing binary software to selectively lie to a specific verifier, coordinating a DDoS attack against backup nodes simultaneously, and exploiting the timing to use the stolen assets productively before emergency pauses could activate. This is not opportunistic hacking. It is a carefully planned, multi-stage infrastructure attack.
Pre-attack staging from Tornado Cash, the 10-hour gap between wallet funding and the exploit, and the disciplined decision to park stolen assets in Aave rather than immediately liquidating them, are all consistent with sophisticated state-actor operational patterns. At time of writing, the 75,700 ETH on Ethereum and 30,765 ETH on Arbitrum attributable to the attacker cluster had not moved for approximately nine hours, which some analysts attributed to