An attacker drained $292 million worth of rsETH from Kelp DAO’s LayerZero-powered cross-chain bridge on Saturday afternoon, making the theft the largest decentralized finance exploit of 2026. The thief extracted 116,500 rsETH, roughly 18% of the token’s 630,000 circulating supply, by spoofing a cross-chain message that tricked the bridge into releasing tokens without any corresponding burn on the source chain. Within hours, Aave, SparkLend, Fluid, Lido, and Ethena froze rsETH-linked markets or paused LayerZero integrations to contain the fallout, and the AAVE token fell more than 10% on panic selling.
A liquid restaking token, or LRT, is a receipt token issued to users who stake ether through services like Kelp that redeploy the stake across multiple validator networks to earn extra yield. The Kelp DAO exploit shows how fragile that plumbing becomes when a single bridge handles reserves across 20 networks.
Key takeaways
- Attackers drained 116,500 rsETH worth $292 million from Kelp DAO’s LayerZero bridge at roughly 17:35 UTC on April 18, 2026.
- Kelp’s emergency multisig paused the bridge 46 minutes later, blocking two follow-up attempts to steal another 40,000 rsETH.
- Aave froze rsETH markets on V3 and V4, with Stani Kulechov confirming Aave’s own contracts were not breached.
- Bad debt across Aave, Compound V3, and Euler now exceeds $236 million, with Aave V3 exposed to roughly $177 million alone.
Published: April 19, 2026 05:00 UTC
How the LayerZero message was forged
Blockchain investigator ZachXBT first flagged the suspicious activity at 14:52 UTC on April 18. According to security firm Cyvers, the attacker exploited a vulnerability in the lzReceive function on Kelp’s bridge contract, the callback that LayerZero endpoints invoke when relaying a cross-chain message. By constructing a forged packet that appeared to originate from a peer chain, the attacker convinced the bridge to mint rsETH on the destination side without burning any on the source side, breaking the one-to-one supply peg that keeps wrapped assets solvent.
Kelp’s pauser multisig froze core contracts at 18:21 UTC, 46 minutes after the first successful drain. Two follow-up attempts at 18:26 and 18:28 UTC, each carrying the same forged LayerZero packet for another 40,000 rsETH (roughly $100 million), both reverted because the contracts had already been paused. Cyvers confirmed the thief swapped the stolen tokens back to Ethereum and Arbitrum and funded gas fees through Tornado Cash, a sanctioned mixer routinely used to launder stolen DeFi funds.
Why Aave, SparkLend, and Lido froze markets
The exploit forced every lender that accepts rsETH as collateral to act within hours. Aave suspended both V3 and V4 rsETH markets, preventing new deposits and borrowing while it reviews existing loans for bad debt exposure. “The rsETH markets on Aave V3 and Aave V4 have been frozen. Aave’s contracts have not been exploited and this is an exploit related to rsETH,” Aave said in an official statement, adding it would “explore ways to offset the deficit” if bad debt accrues.
SparkLend and Fluid matched the freeze, with SparkLend noting it carried zero rsETH exposure at the time of the incident. Stani Kulechov, founder of Aave, said the asset “does not have any borrowing power” on the platform, limiting the scale of cascading liquidations. Lido Finance paused earnETH deposits because of indirect rsETH exposure, and Ethena halted its LayerZero bridges for a six-hour precautionary window.
Bad debt, price damage, and the Drift comparison
On-chain data shows the attacker then collateralized a portion of the stolen rsETH on Aave V3, Compound V3, and Euler to borrow large amounts of wETH, building combined debt positions of more than $236 million. Aave V3 alone faces potential bad debt near $177 million, according to Coingape analysis of the positions. The AAVE token fell 10.27% to $105.73 on the news, and ether slid roughly 3% as traders priced in forced unwinds from restaking pools.
The Kelp DAO exploit edges out the $285 million Drift Protocol hack from April 1 as the largest DeFi loss of 2026. Unlike the Drift case, where Tether stepped in with a $128 million recapitalization, no white-knight backstop has surfaced for Kelp yet. The protocol said it “identified suspicious cross-chain activity involving rsETH” and is working with LayerZero, external auditors, and industry partners on the investigation.
What happens next
Several open questions will shape the next 72 hours. Whether Kelp can negotiate a partial fund return, either through ransom or clawbacks, will determine the final hole in rsETH’s backing. If the attacker continues to move funds through centralized exchanges or stablecoin issuers, pressure to freeze addresses will grow, repeating the tension seen after the Drift exploit when Circle declined to blacklist stolen USDC. Regulators, who have spent April on clarifying DeFi interface rules, are likely to revive questions about LayerZero-style cross-chain messaging and whether restaking bridges need formal risk disclosures.
For rsETH holders, the immediate question is backing. With 116,500 tokens unbacked across more than 20 networks, Kelp will need to either recover the funds, socialize the loss, or find an outside recapitalization partner. Any of those paths will reshape confidence in liquid restaking, a sector that has attracted billions of dollars in deposits on the promise that a single wrapped receipt can travel safely across chains.
Frequently asked questions
What is rsETH and how did the Kelp DAO exploit affect it?
rsETH is the liquid restaking token issued by Kelp DAO against ether staked across multiple validator networks. The attacker stole 116,500 rsETH, roughly 18% of the 630,000-token circulating supply, leaving that portion of the token unbacked by underlying collateral until Kelp resolves the loss.
Was LayerZero itself hacked?
No. The attack exploited how Kelp’s bridge contract handled incoming LayerZero messages through its lzReceive callback, not LayerZero’s core infrastructure. The forged packet tricked Kelp’s code into releasing tokens it should not have, which is a protocol-level vulnerability rather than a messaging layer breach.
How much bad debt did the Kelp DAO exploit create on Aave?
Aave V3 faces potential bad debt of roughly $177 million because the attacker used stolen rsETH as collateral to borrow wETH before repayment became impossible. Aave has frozen rsETH markets on V3 and V4 and said it will “explore ways to offset the deficit” if final losses require protocol action.








