Kelp DAO's liquid staking token potentially exploited for over $100M.
Security & Exploits ·
Kelp DAO's rsETH liquid staking token faced a potential exploit affecting over $100M in value, prompting the protocol to pause its LRTDepositPool contract on Ethereum mainnet after detecting the issue through Immunefi. The incident triggered rapid responses from the team, with both the rsETH contract and the LRTDepositPool entering pause states to limit exposure.
The pause-and-unpause sequence reflects standard incident containment: administrative addresses halted the affected contract following detection, then later resumed operations after initial mitigation. LayerZero, implicated in the incident, issued a public apology and acknowledged architectural shortcomings in its single-verifier setup that contributed to the vulnerability.
Key uncertainties remain around the final loss amount, the root cause's full scope, and whether the pause prevented the full $100M exposure from materializing. The protocol's response timeline and the extent to which user funds were at risk during the window between detection and pause have not been fully detailed in available reports.