KelpDAO exploited for $290M via forged LayerZero bridge message; Aave holding significant bad debt from fallout.
Security & Exploits ·
On April 18, 2026, an attacker exploited LayerZero's cross-chain bridge infrastructure by forging a valid signature to the single verifier protecting KelpDAO's deposits. The attack extracted approximately $290 million in rsETH—roughly 18% of the token's circulating supply—in a single transaction. The attacker then deposited the stolen rsETH into Aave as collateral, borrowed WETH against it, and withdrew before the protocol's emergency multisig could act. Aave's total value locked declined by $6.28 billion within 48 hours, WETH pools reached 100% utilization, and nine protocols froze their markets in response.
The incident exposed tensions over responsibility for the breach. LayerZero attributed the exploit to KelpDAO's single-verifier configuration, while KelpDAO countered that this setup was LayerZero's documented default. Security researchers raised an unresolved question: how the attacker gained root-level access to LayerZero's RPC nodes in the first place. Preliminary attribution points to North Korea's Lazarus Group, marking the second nine-figure DeFi theft linked to the same operation within eighteen days and totaling over $577 million in three weeks.
The fundamental vulnerability remains unclear and largely unaudited. Standard audits of smart contracts found no flaws, yet the verification layer sitting outside audit scope failed completely, exposing a critical gap in DeFi's security model: off-chain infrastructure and cross-chain bridges operate in a blind spot that current industry review practices do not adequately cover.