Kelp DAO exploited for $280M via compromised liquid restaking token; attacker used stolen rsETH as collateral on Aave, triggering protocol freezes across 9 platforms.
Security & Exploits ·
Kelp DAO's liquid restaking token rsETH was compromised in an exploit that resulted in the withdrawal of 116.5k ETH valued at $293M. The attacker then used the stolen rsETH as collateral to borrow ETH on Aave, accumulating significant bad debt and exerting downward pressure on the AAVE token. The exploit's ripple effects triggered market freezes across nine protocols, including Aave V3, SparkLend, Lido Earn, Fluid, Compound, Euler, Upshift, Pendle, and select Beefy and Yearn strategies.
In response, Aave's multisig froze rsETH on its lending market to contain exposure, while Kelp DAO's emergency pauser multisig froze the protocol's core contracts approximately 46 minutes after the drain was completed. Attacker wallets were funded via Tornado Cash, obscuring their origin. The rapid cascade of freezes across multiple platforms underscores the interconnected risk in liquid restaking and collateralized lending.
The incident leaves several details unresolved, including the full extent of bad debt accrued on affected lending protocols, the mechanism by which the rsETH compromise occurred, and whether Kelp DAO has issued a formal public statement beyond protocol-level actions. Market stability and user fund recovery remain contingent on platform-specific mitigation strategies.