KelpDAO exploited for $300M via forged LayerZero lzReceive call; 116,500 rsETH drained from mainnet OFTAdapter with cascading risk to Aave and major DeFi protocols.
Security & Exploits ·
KelpDAO experienced a $300 million exploit involving a forged LayerZero lzReceive call, according to reporting on the incident. The attacker targeted the mainnet OFTAdapter, draining 116,500 rsETH through the fabricated call on LayerZero's EndpointV2. Justin Sun called for negotiations with the attacker, signaling concern over the breach's severity.
The exploit carries cascading risk to downstream protocols. Aave and other major DeFi platforms face potential contagion given their exposure to rsETH and interconnected liquidity pools. The vulnerability in the OFTAdapter's call validation mechanism allowed the attacker to bypass standard authentication checks, exposing a gap in cross-chain bridge security.
Several questions remain unresolved: whether additional funds remain at risk, the attacker's identity and motivations, and the full scope of affected user positions across integrated protocols. Recovery prospects and formal remediation steps from KelpDAO have not yet been detailed.