Skip to main content
AVOID.NET

KelpDAO Bridge Exploit (April 2026)

avoid.net/kelpdao-bridge-exploit-april-202618/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·H72JGF…UPJe

Summary

On April 18, 2026, approximately 116,500 rsETH tokens (valued at roughly $292 million) were fraudulently released from KelpDAO's LayerZero V2 bridge adapter via a forged cross-chain message — the largest single DeFi exploit of 2026. Security firms Mandiant, CrowdStrike, and Chainalysis, as well as LayerZero Labs, attributed the attack with high confidence to TraderTraitor (UNC4899), a North Korean state-linked threat actor operating under the Lazarus Group umbrella. The incident exposed systemic risk in off-chain verification infrastructure and triggered a protracted public dispute between KelpDAO and LayerZero over who bore responsibility for the single-verifier configuration that made the attack possible; LayerZero subsequently acknowledged it had made a mistake.

Connected Entities

19 entities · 60 linked investigations
Relationships
  • KelpDAO Bridge Exploit (April 2026)mentioned withTHORChain(65%)
  • KelpDAO Bridge Exploit (April 2026)mentioned withArbitrum(80%)
  • KelpDAO Bridge Exploit (April 2026)mentioned withMantle(65%)
  • KelpDAO Bridge Exploit (April 2026)mentioned withKelp(70%)
  • KelpDAO Bridge Exploit (April 2026)mentioned withEthena(60%)
  • Ronin Bridgementioned withChainlink(70%)
  • KelpDAO Bridge Exploit (April 2026)mentioned withEthereum(80%)
  • KelpDAO Bridge Exploit (April 2026)mentioned withChainlink(60%)
  • Ronin Bridgementioned withEthereum(80%)
  • KelpDAO Bridge Exploit (April 2026)mentioned withWazirX(70%)
  • + 88 more

Connected Through

19 shared actors · 609 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about KelpDAO Bridge Exploit (April 2026)?
0
Accepted
2
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending7/2/2026, 10:09:16 PM

    TRM Labs H1 2026 report confirms KelpDAO exploit ($292M, April 18, 2026) as the largest single H1 2026 crypto hack, attributed to North Korea-linked actors who compromised RPC nodes on the LayerZero bridge. This was an infrastructure breach, not a smart contract exploit. $292M represents ~30% of all H1 2026 crypto losses.

    avoid-scout

  • Under reviewincriminatingWayback pending7/1/2026, 3:56:32 PM

    On-chain forensic evidence commingling funds from the KelpDAO exploit and the June 2026 Humanity Protocol hack, extending Lazarus Group attribution across both incidents.

    avoid-scout

Timeline(10 events)

6 March 2026

According to LayerZero's incident report, a LayerZero Labs developer was socially engineered into cloning a malicious GitHub repository, which installed malware on their system and allowed the attacker to harvest session keys and access LayerZero's RPC cloud environment.

LayerZero Labs KelpDAO Incident Report

18 April 2026

At approximately 17:35 UTC, attacker executes three transactions, submitting a forged LayerZero cross-chain message. KelpDAO's bridge escrow releases 116,500 rsETH (~$292 million) against a burn transaction that never occurred on the source chain. Stolen rsETH deposited into Aave V3 as collateral to borrow approximately $190–$236 million in WETH.

Hypernative / CoinDesk

19 April 2026

Aave V3 freezes all rsETH and wrsETH reserves across deployments, sets LTV to zero. DeFi contagion triggers reported $8–10 billion in deposit outflows from Aave. Bloomberg reports incident as largest crypto hack of 2026.

CoinDesk / Bloomberg

20 April 2026

LayerZero issues initial statement blaming KelpDAO's 1-of-1 DVN configuration and attributing the attack to North Korea's Lazarus Group. KelpDAO issues a counter-statement claiming LayerZero's default settings caused the disaster.

CoinDesk

23 April 2026

Aave rallies DeFi partners — including Mantle, Lido DAO, EtherFi, and LayerZero — to form the DeFi United coalition to restore rsETH backing and cover Aave's bad debt.

CoinDesk

28 April 2026

DeFi United coalition releases detailed technical recovery proposal for restoring rsETH backing.

CoinDesk / The Block

5 May 2026

KelpDAO publishes detailed memo asserting that LayerZero personnel directly approved the single-verifier configuration across approximately eight integration meetings over roughly two and a half years. KelpDAO announces migration of rsETH bridging from LayerZero to Chainlink CCIP.

CoinDesk / Unchained Crypto

9 May 2026

LayerZero reverses course, publicly admitting: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions. We own that.' LayerZero announces it will no longer service 1-of-1 DVN configurations and will migrate all defaults to a minimum of 3-of-3.

CoinDesk

18 May 2026

LayerZero Labs publishes its full public incident report detailing the attack timeline, social engineering vector, RPC compromise methodology, and attribution to DPRK TraderTraitor unit.

LayerZero Labs Incident Report

25 May 2026

KelpDAO and Aave jointly announce that rsETH has been fully restored. The final tranche of 20,373.7 rsETH is transferred to the LayerZero lockbox contract, completing recovery approximately five weeks after the exploit. All Aave markets and rsETH operations confirmed as functioning normally.

CryptoTimes / NFT Plazas
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 30 of 33 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 6/21/2026, 5:06:27 PM

last updated: 9/20/2026, 9:26:18 PM

3 views

avoid.net — verified advice for a post-truth world