KelpDAO's rsETH bridge exploited for $292M via single-signer LayerZero DVN, allowing attacker to mint unbacked tokens and borrow against them on Aave.
Security & Exploits ·
On April 18, 2026, an attacker minted 116,500 rsETH—roughly 18% of KelpDAO's circulating supply and worth approximately $292 million—by exploiting a single point of failure in the protocol's LayerZero bridge. The attacker forged a cross-chain message claiming tokens were being transferred from another chain to Ethereum mainnet, but KelpDAO's bridge was configured to require approval from only one Decentralized Verifier Network (LayerZero Labs) before releasing tokens from escrow. Since this single DVN validated the fraudulent packet, the escrow contract released the unbacked rsETH directly to the attacker's wallet.
The mechanics of the bridge left it vulnerable to this forgery. KelpDAO uses a LayerZero OFT adapter to move rsETH across chains including Arbitrum, Base, and Linea; when tokens leave Ethereum, they are locked in escrow and minted on destination chains. The configuration required only one DVN signature and accepted no optional verifiers, meaning a single compromised or malicious verification source could approve any transfer. The attacker then immediately used the minted tokens as collateral on Aave, borrowing approximately $236 million in WETH against the worthless collateral.
The core restaking contracts and EigenLayer delegations remain intact, and legitimate user deposits backing rsETH on mainnet have not been affected. However, the exploit represents the largest single DeFi extraction of 2026 so far. KelpDAO and LayerZero have committed to post-mortems, though final figures on bad debt, compensation, and any supply migration remain uncertain as of the initial reporting window.