KelpDAO's LayerZero bridge exploited via 1-of-1 DVN misconfiguration, allowing attacker to mint $292M rsETH and borrow $236M WETH from Aave, creating $177M bad debt.
Security & Exploits ·
On April 18, 2026, an attacker minted 116,500 rsETH—roughly 18% of KelpDAO's circulating supply and worth approximately $292 million—through KelpDAO's LayerZero bridge by exploiting a single-signer configuration on the bridge's validator stack. The unbacked tokens were immediately deposited into Aave as collateral, from which the attacker borrowed approximately $236 million in WETH, creating roughly $177 million in bad debt to the protocol.
The vulnerability lay not in KelpDAO's restaking contracts or EigenLayer integrations, which remained intact, but in the bridge infrastructure itself. LayerZero's OFT adapter for rsETH was configured to require attestation from only a single Decentralized Verifier Network (DVN), allowing a forged cross-chain message to instruct the mainnet escrow to release tokens without legitimate authorization. The attack succeeded in a single transaction that spoofed an lzReceive call, bypassing the multi-signature safeguards that should have protected cross-chain token movements.
KelpDAO and LayerZero have committed to post-mortems, though final figures on compensation and supply migration remain uncertain as of April 19, 2026. The event marks the largest single DeFi extraction of the year so far and is expected to trigger the first real-money slashing event on Umbrella's oracle insurance product.