KelpDAO bridge contract exploited for $293.7M in rsETH, triggering cross-protocol contagion with Aave V3 and Compound freezing markets.
Security & Exploits ·
KelpDAO suffered a major exploit of its bridge contract, resulting in the theft of approximately $293.7 million in rsETH. The attacker subsequently converted the drained funds into ETH. The project team confirmed the incident and began collaborating with security experts to address the vulnerability.
The breach triggered contagion across multiple protocols, with Aave V3 and Compound freezing markets to contain downstream risk exposure from the stolen assets circulating through the ecosystem. The incident marks the largest security breach by USD value in 2026.
The full scope of affected positions and the timeline for market recovery remain unclear, as does the identity of the attacker and whether recovery of any stolen funds is possible.