KelpDAO/LayerZero exploit drains $290M in the largest crypto hack of 2026, raising questions about DeFi security and risk management in an AI-augmented threat landscape.
Security & Exploits ·
On April 21, 2026, KelpDAO's liquid restaking token rsETH was compromised in what became the largest DeFi exploit of 2026, with attackers draining approximately $290 million. An attacker preliminarily identified as North Korea's Lazarus Group exploited KelpDAO's single-verifier configuration on its LayerZero omnichain fungible token bridge, unlocking 116,500 rsETH from the Ethereum mainnet escrow. The stolen tokens were immediately deposited as collateral across Aave, Compound, and Euler, primarily on Ethereum and Arbitrum, where the attacker borrowed an estimated $236 million in WETH and wstETH.
The immediate fallout cascaded through DeFi markets. Aave froze rsETH and related markets across all deployments, while primary stablecoin markets reached 100% utilization, leaving depositors unable to withdraw. Estimated bad debt ranges from $123.7 million to $230.1 million depending on loss allocation assumptions. Major DeFi projects halted their LayerZero OFT bridges, and withdrawal pressure extended to unrelated protocols, triggering a $15 billion drop in total value locked across DeFi.
The Arbitrum Security Council took emergency action to freeze 30,766 ETH and transfer it to a governance-controlled wallet, though the attacker began moving funds to new addresses in an apparent laundering effort. As of Tuesday morning, Aave had reopened WETH markets on Ethereum, though they remained at full utilization. The situation remains in flux, with final figures on bad debt and resolution paths pending further disclosures from KelpDAO, Aave governance, and LayerZero.