CryptoReal
CASE FILE — Apr 24, 2026

How One Forged Cross-Chain Message Cost KelpDAO $290 Million and Nearly Broke Aave

Nobody breached KelpDAO's smart contracts. They breached the single piece of infrastructure KelpDAO's bridge was built to trust.

On April 18, 2026, an attacker manipulated the lone verifier sitting between LayerZero's cross-chain messaging system and 116,500 rsETH in user deposits — roughly 18 percent of the token's entire circulating supply — held in KelpDAO's bridge. About $290 million disappeared. The contract that released the funds behaved exactly as it was built to: it saw what looked like a valid signed message and executed on it.

The theft itself was only the opening move. The stolen rsETH was immediately deposited into Aave as collateral, used to borrow real WETH against it, and moved out before the protocol's emergency multisig could gather enough signers to pause anything. Within roughly 48 hours, Aave's total value locked fell by $6.28 billion, WETH pools hit 100 percent utilization and trapped depositors who hadn't withdrawn in time, and nine separate protocols froze markets in response.

On April 20, Arbitrum's Security Council used its emergency powers to forcibly move 30,766 ETH out of one of the attacker's wallets — a containment move that generated almost as much controversy as the exploit itself.

LayerZero's own post-incident statement pinned the root cause on KelpDAO's choice to run a single-verifier ("1-of-1") configuration. KelpDAO countered that this exact configuration was LayerZero's documented default. Independent researchers noted that neither side has fully explained how the attacker obtained root-level access to LayerZero's RPC infrastructure in the first place.

Preliminary attribution points to North Korea's Lazarus Group — making this the second nine-figure DeFi theft in eighteen days tied to the same state-sponsored operation, with more than $577 million pulled out of DeFi protocols across those three weeks combined. Every audit KelpDAO had commissioned had come back clean, and every on-chain check functioned as intended — because the compromised verification layer sat entirely outside the scope of any of those audits.

01The Discovery Timeline

The first public flag came from researcher Vladimir S. (@officer_secret), who posted shortly after the drain transaction cleared that KelpDAO's liquid staking token had "potentially [been] exploited for over $100M." That figure was an underestimate — the true scale hadn't yet been mapped, and the attack had already concluded before most of the industry had even registered it was happening.

Thirty-six minutes later, PeckShield posted a terse public alert tagging KelpDAO directly, along with a single Etherscan link and no dollar estimate.

Attack transaction: 0x1ae232da212c45f35c1525f851e4c41d529bf18af862d9ce9fd40bf709db4222

ZachXBT posted to Telegram shortly after, naming six attacker addresses, confirming Tornado Cash funding, and revising the estimate upward to "$280M+ stolen ... on Ethereum and Arbitrum." Security firms followed in quick succession: CertiK confirmed roughly $290 million transferred, tracing most of it to two addresses, while Cyvers put the figure at $293.7 million drained from the rsETH Adapter, already split across chains — approximately $178 million on Ethereum and $72 million on Arbitrum — with the proceeds routed through Tornado Cash via intermediate wallets. CertiK corroborated the primary addresses within a couple of hours.

Attacker addresses identified:

KelpDAO's own statement did not arrive until roughly ninety minutes after Vladimir S.'s initial post, and it contained no damage estimate — only confirmation that something had happened and a list of partners it was now consulting: "Earlier today we identified suspicious cross-chain activity involving rsETH. We have paused rsETH contracts across mainnet and several L2s while we investigate. We are working with LayerZero, Unichain, our auditors and top security experts on RCA."

By the time that statement went out, the borrowed WETH had already left Aave and the protocol was already accumulating bad debt. The drain itself had concluded 46 minutes earlier; all the multisig managed to do in that window was pause an already-empty vault. Aave contributor Marc Zeller did not wait for any official word, posting his own alert to depositors: "If you have WETH on Aave V3 Core, withdraw now, ask questions later." By the time KelpDAO's confirmation went live, the rsETH was already sitting as Aave collateral and the WETH borrowed against it was already gone.

02How the Verification Layer Actually Broke

rsETH is KelpDAO's liquid restaking token: users deposit ETH, the protocol routes it through EigenLayer, and depositors receive rsETH as a yield-bearing receipt. By April 2026 rsETH was live across more than 20 networks — including Arbitrum, Base, Mantle, Linea and Unichain — all of them tied back to a single custody pool on Ethereum mainnet via LayerZero's OFT bridging standard.

That shared custody pool is where the exposure lived. Bridging rsETH away from Ethereum locks the tokens in an adapter contract on mainnet; an equivalent amount is minted on the destination chain. Bridging back reverses the process — the destination burns its tokens, and Ethereum releases the corresponding amount from the shared pool. Before the attack, that pool held roughly 116,723 rsETH; afterward, only 223 remained.

Security for that release process depends on LayerZero V2's Decentralized Verifier Networks (DVNs). Each DVN independently watches the source chain, confirms a transaction occurred, and submits a signed attestation to the destination chain; once enough DVNs have signed, the transfer is authorized to proceed. LayerZero's architecture supports — and recommends — running several independent DVNs so that consensus among multiple parties is required before funds move.

KelpDAO's actual configuration for the Unichain-to-Ethereum route told a different story: a required DVN count of 1, an optional DVN count of 0, and an optional-DVN threshold of 0, with the sole required verifier being a single LayerZero-operated address labeled "LayerZero: DVN" on Etherscan. One verifier. No redundancy. A single compromised signature would be enough to move funds.

That is precisely what the attacker engineered. LayerZero's post-mortem describes the method as RPC poisoning, though outside researchers have disputed that characterization. Banteg's analysis argues this wasn't an external poisoning attack at all, but a perimeter breach: the attackers got inside LayerZero's own trust boundary, obtained its internal RPC node list, compromised two of the nodes the DVN relied on, and replaced the op-geth binaries running on them — a targeted, supply-chain-style implant rather than a purely network-level attack. LayerZero's own post-mortem adds that the attackers then DDoS'd the remaining uncompromised RPC nodes, forcing full failover onto the poisoned infrastructure. One of the compromised nodes has been identified by Banteg's follow-up research as operated by QuickNode.

The malicious nodes were narrowly targeted: they served fabricated data — asserting a transaction had occurred on Unichain — exclusively to the DVN's own IP addresses, while returning accurate responses to every other caller, including LayerZero's own monitoring systems. Once the operation concluded, the malicious binaries self-deleted, erasing logs, configuration, and most forensic traces.

The attacker's entire seed capital for the operation was strikingly small: approximately $230 in ETH sourced from Tornado Cash roughly ten hours before the drain.

Funding transaction: 0xcb2ee450d6e770216dc3061750b4ac5b5fa494666bcf7eaa936411733e2ef7ee

With the compromised DVN reporting fabricated chain state, the attacker submitted a forged packet claiming that 116,500 rsETH had been locked and burned on Unichain. The DVN's internal 2-of-3 multisig signed off on it, certifying the packet as valid. Ethereum's endpoint contract performed its only check — hash equality between the packet and the signed payload — which passed, since the hash matched what had been signed. The adapter released the funds accordingly.

Forged packet details: nonce 308; recipient 0x8B1b6c9A6DB1304000412dd21Ae6A70a82d60D3b; amount 0x1b1ff0ed00 (116,500 rsETH); gas 94,456; GUID 0x3f4510d855cf3a805fec59daafae640d290749b7bf1e5450f91b5fb0018b3b4e.

The forgery is provable on-chain in three separate ways: Unichain's outbound nonce never advanced past 307, meaning nonce 308 never actually existed on the source side; Unichain's total rsETH supply at the time was only 49.26 rsETH, making it physically impossible to have burned 116,500; and no Transfer event, no burn to the zero address, and no PacketSent event appear anywhere on Unichain for the relevant block window. For comparison, nonce 307 — a genuine transfer of 0.006 rsETH two days earlier — shows exactly what a legitimate bridge transaction looks like on-chain: a burn on Unichain, a release on Ethereum, and nonces advancing cleanly on both sides.

The attacker had queued a second forged packet as well — nonce 309, structured identically, targeting an additional 40,000 rsETH worth roughly $100 million. Two delivery attempts were made and both reverted; KelpDAO's emergency multisig had just enough time to freeze the intended recipient address. That second packet's payload hash remains committed on Ethereum's endpoint, permanently undeliverable.

Whether LayerZero's account of the breach is complete remains an open question — specifically how the attacker obtained root-level access sufficient to swap binaries across independent infrastructure clusters has not been publicly detailed. What isn't disputed is the structural condition that enabled the theft: no reentrancy bug, no integer overflow, no signature replay, no flash loan — purely a verification-layer failure enabled by a configuration choice. LayerZero maintains it communicated DVN-diversification best practices to KelpDAO, which chose to keep the 1-of-1 setup regardless; KelpDAO maintains that setup was LayerZero's own documented default, affirmatively confirmed as appropriate.

Sums referenced in this case file

03Tracing the Stolen Funds

Rather than dumping 116,500 rsETH on the open market — which would have crashed the price immediately and capped how much value could actually be extracted — the attacker executed a pre-planned laundering sequence. Within minutes of the drain, the stolen rsETH was spread across eight pre-staged wallets, each following an identical pattern: deposit rsETH into Aave V3 as collateral, switch to eMode category 3, borrow ETH at roughly 99 percent effective loan-to-value, then forward everything to a central collector address. Just 27 minutes after the initial drain, the Ethereum-side collector already held 75,700 ETH from five of those branch wallets alone.

The largest single branch, 0x1F4C1c2e610f089D6914c4448E6F21Cb0db3adeF, received 53,000 rsETH and immediately opened a position on Aave V3, pulling ETH out in four sequential withdrawals over three minutes before forwarding the entire balance to the collector. It supplied 53,000 rsETH, borrowed approximately 52,440 ETH, and — as of the writing of the original source — that position remained open, with the rsETH collateral left behind as worthless, unliquidatable backing.

Across all eight branches combined, the attacker supplied 89,567 rsETH to Aave and extracted 82,650 WETH plus 821 wstETH — worth roughly $221 million, $190 million and $2.3 million respectively. The collector address was 0x5d3919F12bCc35c26Eee5F8226A9bee90c257Ccc. Smaller amounts were also run through Compound V3 and Euler, generating roughly $39.4 million and $840,000 in additional borrows before those markets, too, were frozen. Geographically, the extraction split almost immediately: about $178 million consolidated on Ethereum mainnet and about $72 million landed on Arbitrum.

Arbitrum turned out to be where the first real containment happened. On April 20, its 12-member Security Council — with nine of twelve voting in favor — used a privileged system-level transaction to forcibly relocate 30,766 ETH from the attacker's Arbitrum address into an intermediary frozen wallet, completing the freeze at 11:26 PM ET. The frozen amount is separately cited as 30,765 ETH, worth approximately $73.6 million, held at 0x0000000000000000000000000000000000000DA0 pending an Arbitrum governance vote on release conditions.

The move worked, but it wasn't uncomfortable-free. Critics argued that a governance council's ability to unilaterally seize funds by decree undermines any credible claim to decentralization. Council member Griff Green said publicly that the decision "was not made lightly," describing "countless hours of debates, technical, practical, ethical and political." Marc Zeller was blunter: "Every cell of my being is meant to be against what Arbitrum just did. Yet I understand their decision. People getting their money back matters more than convictions that would allow unc Kim to walk away with a payday."

With the Arbitrum funds locked down, the attacker shifted focus to the Ethereum-side holdings. Roughly 75,701 ETH (about $175 million) began moving out through THORChain, Umbra, Chainflip and the BitTorrent chain, with Bitcoin as the consistent end destination — THORChain enabling direct chain-to-chain swaps without custodians or KYC, and Umbra providing stealth-address privacy, neither requiring identity verification. The pattern mirrors the 2025 Bybit hack's exit playbook, in which about 83 percent of stolen ETH was converted to Bitcoin, with 72 percent of that flow passing through THORChain alone. On-chain researcher tanuki42 noted that the KelpDAO proceeds were already commingling with funds from other TraderTraitor-linked operations, including the 2025 BTCTurk hack and Bybit — suggesting shared third-party laundering infrastructure across campaigns. By the time investigators had mapped the exits, less than 0.768 ETH remained in the original exploiter address, and the wallet that had received the initial 116,500 rsETH had been almost entirely emptied.

04Attribution and a Widening Pattern

LayerZero's incident statement, published April 19, named North Korea's Lazarus Group — specifically its TraderTraitor subunit — as the preliminary attribution, citing indicators consistent with prior state-sponsored campaigns: Tornado Cash pre-funding, self-deleting malware, and the surgical precision of a multi-stage infrastructure compromise that left few loose ends.

Elliptic had already tracked Drift as the eighteenth DPRK-attributed crypto operation of 2026; KelpDAO followed just over two weeks later, pushing the year's DPRK-linked total past $300 million by the time that figure was published — and closer to $600 million once KelpDAO was added. The two operations, however, could not have looked more different in execution. Drift was a six-month social-engineering campaign: attackers attended industry conferences, cultivated genuine relationships with contributors, deposited $1 million of their own capital into the protocol, and waited. The entry point was human trust; the weapon was patience. KelpDAO required none of that — no conference badges, no cultivated rapport, no months-long cover story. It needed only root access to an RPC node list, two compromised binaries, a DDoS, and one forged packet. Start to finish, the active operation took under two hours, even if the preparatory reconnaissance almost certainly took much longer.

That contrast points to something researchers see as a meaningful shift: Drift demonstrated that even in-person relationships can be compromised by operatives running fabricated identities, while KelpDAO demonstrates that compromising people may not be necessary at all when the verification layer itself can be attacked directly — no phishing email, malicious repository, or fake app required. LayerZero has disclosed that the attacker obtained its RPC node list and swapped binaries across two independent, unconnected infrastructure clusters; achieving that undetected, while serving forged data to exactly one IP address and clean data to everyone else, implies either an extended reconnaissance period or pre-existing access dating back weeks or months before the April 18 drain. LayerZero has not explained how that initial access was obtained.

For scale: North Korea-linked crypto theft topped $6.75 billion by the end of 2025, with the February 2025 Bybit hack alone accounting for $1.5 billion and the 2022 Ronin bridge hack for $625 million. Drift cost $285 million on April 1; KelpDAO cost $290 million seventeen days later — $577 million extracted from two DeFi protocols in barely two weeks, attributed to the same state actor, using two entirely different methods. One took six months of human infiltration; the other took a compromised RPC list.

05Contagion Across the Rest of DeFi

rsETH had earned whitelisted-collateral status across most of DeFi's major lending markets — reviewed by risk managers including Chaos Labs and LlamaRisk, who calibrated supply caps, WETH borrow caps, and liquidation thresholds around what rsETH had always been: a conservatively backed liquid restaking token with an uneventful price history. Every one of those assumptions held until 17:35 UTC on April 18, the moment 89,567 unbacked rsETH landed on Aave as collateral and 82,650 WETH was borrowed out against it. At that point, the very risk parameters designed to protect Aave became the mechanism transmitting the damage. Aave hadn't been hacked; it had simply functioned exactly as designed, at a scale the design had never anticipated.

Part of what made the shock so severe: roughly 98.5 percent of the collateral backing WETH borrows on Aave came from ETH liquid staking tokens, meaning the WETH pool was funding almost entirely leveraged LST carry trades rather than a diversified loan book. Within hours, WETH pool utilization hit 100 percent — every deposited WETH was on loan, leaving nothing available for withdrawals. The dynamic resembled a pawnshop that had just taken in counterfeit gold, handed over real cash against it, and was left holding worthless collateral while every other customer found the shop's cash drawer empty. A straightforward bank run followed: whoever understood the situation and withdrew first got out whole, while everyone else waited. MEXC withdrew $431 million; Abraxas Capital withdrew $392 million; a whale wallet tagged to Nonco pulled out $405.7 million. By the time the exodus tapered off, $8.45 billion had left Aave within 48 hours, contributing to a $13.21 billion drop in DeFi's aggregate TVL. Aave's own token fell 18 percent on day one, and the protocol lost its position as DeFi's largest lender over the course of a single weekend. aWETH, normally pegged close to 1:1 with WETH, traded at an 8 percent discount as the market priced in impairment, and Aave's share of total DeFi lending deposits fell from roughly 68 percent to under 61 percent within four days — its lowest level in more than a year.

The liquidity crunch spilled sideways. With ETH pools drained, users unable to withdraw WETH instead borrowed against their stablecoin deposits just to access liquidity, driving a roughly $300 million surge in USDT-collateralized borrowing within 24 hours. Monetsupply, head of strategy at Spark, described the dynamic: "We're now seeing some negative secondary effects of illiquidity in Aave stablecoin markets. Because users can't withdraw due to 100% utilization, there has been a ~$300 million increase in borrowing with USDT collateral in just the past day since the rsETH exploit."

Aave's formal incident report, published April 20, laid out two possible loss-allocation scenarios depending on how KelpDAO ultimately treats the shortfall. Under uniform socialization across all rsETH holders, the depeg lands around 15 percent and Aave's bad debt comes to roughly $123.7 million, with $91.8 million of that falling on Ethereum Core. Under the harsher alternative — isolating losses to L2 rsETH only — the L2 collateral haircut reaches 73.54 percent and bad debt climbs to $230.1 million, concentrated on Mantle, Arbitrum and Base. Aave clarified that the adapter drain only affected the cross-chain float — the bridged L2 copies — while mainnet rsETH remains backed by Kelp's actual underlying ETH staking deposits, untouched by the exploit; this distinction is exactly why the two scenarios produce such different numbers for Ethereum Core's exposure. DeFiLlama co-founder 0xngmi laid out the three practical options publicly: socialize losses across everyone, isolate losses to L2 holders (which he called "rugging rsETH holders on L2s"), or attempt to restore balances to a pre-exploit snapshot, which he called "very hard to do" given how far the funds had already moved. As of the report, KelpDAO had not committed to any of the three.

Notably, this risk had been flagged well before the exploit: in February 2025, during Aave governance discussions about listing rsETH on Arbitrum and Base, BGD Labs explicitly warned about relying on a single DVN and recommended a multi-DVN setup. That recommendation was raised through the proper governance channel and then set aside. Fourteen months later, the scenario it warned about played out at $290 million scale.

The attacker's Aave positions remain open, the posted rsETH collateral unredeemable while KelpDAO's contracts stay frozen, with no realistic path to profitable liquidation. That bad debt continues to accrue interest on loans that will never be repaid while governance decides who bears the cost. Aave's Umbrella insurance module holds 23,507 aWETH (about $54 million) — covering only part of the $91.8 million Ethereum Core shortfall under the first scenario — and by the time the incident report was published, roughly 80 percent of that module (about 18,922 aWETH) had already entered the unstaking cooldown queue, as stakers rushed to exit before the backstop could be triggered against them. Aave's service providers subsequently recommended pausing the Umbrella module to stop further capital flight. The DAO treasury separately holds $181 million and has received additional ecosystem backstop commitments, though none of that is automatically triggered under the second scenario, leaving L2 markets largely on their own. On April 21, Aave took a first step toward normalcy, unfreezing WETH supply on the Ethereum Core V3 market (with WETH LTV still set to zero), while WETH markets on Ethereum Prime, Arbitrum, Base, Mantle and Linea stayed frozen.

The freeze list kept growing through the weekend. SparkLend, Fluid, Euler, Aave V3, Athena, Compound, Yearn, LayerZero, Pendle, Beefy and Upshift all paused rsETH-related markets. Lido disclosed $21.6 million in rsETH exposure through its EarnETH product (about 9 percent of that vault), backstopped by a $3 million first-loss buffer funded by the Lido DAO treasury; as of April 23, EarnETH deposits and withdrawals remained paused while the vault curator worked to unwind affected positions. Morpho CEO Paul Frambot reported only about $1 million in exposure across two isolated markets, with Morpho's isolated-market design preventing any spillover — arguably the one clean containment success of the entire incident.

A second wave of pauses followed among protocols with zero rsETH exposure, which froze anyway simply because their own bridges ran on LayerZero and they couldn't yet confirm their configurations were safe: Ethena paused its LayerZero OFT bridges for six hours; EtherFi paused weETH and eETH bridging; Curve paused CRV bridging across BNB, Sonic, Avalanche, Fantom, Kava and Etherlink; WBTC's LayerZero OFT was paused; and TRON, Pengu, the MOCA Foundation, ApeChain, the Morpho token on Arbitrum, and Solv Protocol all followed suit. One researcher tracking the pauses in a running thread stopped counting once the tally passed 31 — the true number was almost certainly higher. Stablecoin infrastructure provider Brale, which runs its own LayerZero DVN, disclosed that its DVN had also been running as a single node; on recognizing the same antipattern in KelpDAO's incident statement, Brale shut its DVN down that Saturday night, with no impact to its customers. The disclosure underscored a broader point: KelpDAO wasn't the only 1-of-1 deployment running in production — it was simply the one that got targeted.

Reported exposure to frozen Aave liquidity extended well beyond the direct participants: Mellow ($338M), Avant ($310M), Upshift ($302M), Kiln ($245M), CIAN ($199M), Mantle ($164M), World Liberty Financial ($123M), YuzuMoney ($80M), MidasRWA ($46.6M), templedao ($62M), ForesightVen ($50M) and Resolv Labs ($33M), among others still tallying their numbers. DeFiLlama's broader ecosystem TVL gauge lost $13.21 billion over the same 48-hour window.

Mantle was among the first to move toward a recovery framework, confirming on April 21 that it was actively coordinating with Aave and affected protocols on a structured plan, potentially including its own treasury. That cooperation is also self-interested: Mantle faces the largest proportional exposure under the harsher loss scenario, with a 71.45 percent WETH shortfall. By April 24, Mantle was one of nine named partners — alongside EtherFi, Ethena, Lido, Golem, Ink Foundation, Tydro, Frax and LayerZero — who had each pledged support, in their own capacity, to a joint recovery initiative dubbed "DeFi United."

06The Public Fight Over Blame

The drain concluded at 17:35 UTC on April 18. By the following Monday, a second confrontation was underway — this one conducted in public, between LayerZero and KelpDAO, the two parties that shared the infrastructure that failed.

LayerZero's incident statement, published April 19, detailed the attack and attributed it to Lazarus Group before pivoting to accountability: "LayerZero and other external parties previously communicated best practices around DVN diversification to Kelp DAO. Despite these recommendations, Kelp DAO chose to utilize a 1/1 DVN configuration. A properly hardened configuration would have required consensus across multiple independent DVNs, rendering this attack ineffective even in the event of any single DVN being compromised." The implication was direct: KelpDAO had been warned and hadn't acted on it.

KelpDAO's rebuttal, issued the same day, told a different story: "The 1-of-1 DVN setup is the configuration documented in LayerZero's documentation and shipped as the default for any new OFT deployment. Kelp has operated on LayerZero infrastructure since January 2024 and has maintained an open communication channel with the LayerZero team throughout. The question of DVN configuration came up during Kelp's L2 expansion, and defaults were affirmatively confirmed as appropriate at that time." KelpDAO further stressed a point it argued LayerZero's own statement had sidestepped: "This was an attack on LayerZero's infrastructure. Kelp's own systems were not involved in building or operating that infrastructure." The compromised DVN was not a third party KelpDAO had selected or vetted — it was LayerZero Labs' own verifier, running on LayerZero Labs' own RPC nodes, breached via LayerZero Labs' own internal node list. That makes the argument that KelpDAO should have diversified away from LayerZero's infrastructure as protection against LayerZero's infrastructure being compromised a genuinely awkward one.

CoinDesk, which had previewed KelpDAO's memo ahead of publication, reported separately that roughly 40 percent of applications currently running on LayerZero use a 1-of-1 configuration. An independent on-chain review of about 3,500 LayerZero V2 OApp deployments over a 90-day window found 1,111 running a strict 1-of-1 DVN setup, 28 of which had bridged more than $100,000 and 10 of which had bridged more than $1 million. A Dune dashboard tracking LayerZero OApp DVN configurations reinforced the same conclusion: single-DVN setups were common, not exceptional, spanning protocols of every size and frequently naming LayerZero Labs itself as the sole required verifier — the same infrastructure, the same single point of failure that had just cost KelpDAO $290 million. Banteg published a running list of protocols still operating 1-of-1 configurations in the aftermath. Separately, Bartek.eth found that in a scan of 185 LayerZero applications, only 10 had changed the default security settings at all, and of those, exactly one — an experimental deployment by L2Beat — had changed both the Oracle and Relayer settings. Every other production application had shipped with the defaults intact.

LayerZero's position is that its architecture is intentionally modular: applications are responsible for their own security configuration, and LayerZero's role is to provide infrastructure rather than enforce specific settings. It maintains that it communicated multi-DVN best practices to KelpDAO directly and that KelpDAO chose to keep the 1-of-1 setup anyway. KelpDAO counters that its communication channel with LayerZero had been open since July 2024, that no specific instruction to change the rsETH DVN configuration was ever given, and that during its L2 expansion the default setup was affirmatively confirmed by LayerZero as appropriate. Both accounts can be simultaneously true — documentation can present a minimal example while informal guidance recommends something stronger, and a team can hear that guidance and still ship the default anyway. None of it changes what happened on-chain.

In direct response, LayerZero announced it will no longer sign or attest to messages for any application running a 1-of-1 DVN configuration, and that it is reaching out to all such applications to help them migrate to redundant multi-DVN setups. That policy change came after the breach, not before it — arguably the clearest public acknowledgment that the "default" configuration was never actually adequate for production use at this scale. CoinDesk noted that KelpDAO's memo, framed around reliance on LayerZero's documentation, defaults and guidance, reads less like a technical post-mortem and more like the opening position of a liability dispute.

07Where Things Stand

KelpDAO published a recovery accounting on April 24. The original shortfall stood at 163,200 ETH. Of that, Kelp had independently recovered 40,300 rsETH (roughly 43,000 ETH worth), and the Arbitrum Security Council's freeze secured a further 30,700 ETH, leaving a remaining gap of approximately 89,500 ETH. Confirmed public pledges from Mantle, Stani Kulechov, EtherFi, Lido and Golem total 43,500 ETH toward closing that gap, with Ethena, Ink Foundation, Tydro, Frax and LayerZero each committing support in their own capacity. Under the joint "DeFi United" recovery effort, Stani Kulechov personally pledged 5,000 ETH, EtherFi proposed 5,000 ETH, and Lido proposed 2,500 stETH.

As of April 24, Aave's TVL sits at roughly $15 billion, down from about $26 billion at the time of the exploit. The attacker's 75,700 ETH has already been fully converted to Bitcoin — a process completed in under 36 hours, mostly via THORChain — meaning that portion of the exit is effectively finished and unrecoverable. KelpDAO's contracts remain paused, and the full picture of rsETH's backing across its 20-plus deployed chains stays unresolved pending a reconciliation report that has not yet been published. Aave's own bad-debt exposure sits somewhere between $123 million and $230 million, with the exact figure hinging entirely on decisions KelpDAO has not made. On April 23, Aave re-paused rsETH reserves across Ethereum Core, Arbitrum, Base, Mantle and Linea, citing the goal of "recovering additional funds as the recovery plans progress." Ethereum WETH stakers in the Umbrella module face near-total slashing, since the deficit there is roughly twice the size of the module itself; Arbitrum WETH suppliers have no comparable backstop at all, since Umbrella doesn't cover L2 deployments, pushing that shortfall directly onto DAO-level mechanisms. Issuing new AAVE tokens to cover the residual gap looks like the most politically viable path forward — meaning existing token holders may end up diluted for a breach that never touched a single line of Aave's own code.

Roughly $71 million in ETH remains frozen by the Arbitrum Security Council, an outcome that would have looked implausible before this incident and that still troubles decentralization advocates. Roughly $175 million has already moved further into Bitcoin's rails than any blockchain investigator is likely to trace. LayerZero's decision to stop signing for 1-of-1 configurations is a policy that arguably should have predated this $290 million loss rather than followed it, and Banteg's list of protocols still running the same configuration KelpDAO had is a long one.

Resolving the fallout — governance votes, loss allocation, possible legal exposure — will take months, and some of the damage will likely never fully unwind. What stands out is less the dollar figure or the Lazarus attribution, both of which now fit an established pattern, and more the shrinking amount of human involvement required: Drift needed six months of in-person social engineering; KelpDAO needed a node list, two compromised binaries, a DDoS, and a single forged packet. The infrastructure layer — bridges, verifiers, RPC nodes — is increasingly where the real risk lives, even as much of the industry continues focused on the smart-contract layer beneath it.

DeFi's composability is exactly what made rsETH worth holding across 20 different chains — and exactly what turned a single bridge exploit into an estimated $200 million bad-debt crisis at a lending protocol that was never itself compromised. One forged message contributed to roughly $13 billion in ecosystem-wide TVL being erased within 48 hours, and protocols with no direct rsETH exposure froze their own bridges purely because the shared trust model underneath the entire LayerZero ecosystem had just been shown to be breakable.

AaveKelpDAOLayerZero
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.