The Arbitrum Security Council froze 30,766 ETH worth approximately $71 million early Tuesday, the latest development in the fallout from the $292 million KelpDAO exploit that rocked decentralized finance markets over the weekend. The emergency action — executed at 11:26 p.m. ET on Monday — marks the largest successful asset freeze linked to a DeFi hack since the Euler Finance recovery in 2023, and represents roughly one quarter of the total funds stolen.
A decentralized autonomous organization, or DAO, is a blockchain-governed protocol where decisions are made collectively by token holders rather than a central company or authority.
Key Takeaways
- Arbitrum’s Security Council froze $71M in ETH on April 20 with law enforcement involvement, linked to the April 19 KelpDAO exploit
- The original hack drained 116,500 rsETH ($292M) from Kelp’s LayerZero-powered bridge, becoming 2026’s largest DeFi exploit
- DeFi total value locked fell $13.2 billion in 48 hours; Aave faces up to $230 million in bad debt from the contagion
- LayerZero and North Korea’s Lazarus Group have been identified as responsible for the exploit’s execution vector
Published: April 21, 2026 — Updated as of 9:00 AM UTC
How the $292M exploit unfolded
On Saturday, April 19, attackers drained 116,500 rsETH from Kelp DAO’s LayerZero-powered cross-chain bridge in what became the largest DeFi exploit of 2026, surpassing the $285 million Drift attack attributed to North Korea-linked actors on April 1. The attackers compromised two remote procedure call (RPC) nodes that LayerZero’s verifier relied on, replacing their software with malicious versions that falsely reported a legitimate cross-chain message. That message instructed Kelp’s bridge to release the rsETH to an attacker-controlled address.
Kelp DAO’s rsETH is a liquid restaking token — a receipt asset that represents ETH deposited into EigenLayer’s restaking protocol. When the stolen rsETH flooded into Aave V3 as collateral and attackers borrowed wrapped ETH against it, the tokens began collapsing in value. That triggered a cascade of under-collateralized positions, leaving an estimated $196 million in bad debt concentrated in Aave’s rsETH/wETH market on Ethereum. Aave’s total value locked fell from $26.4 billion on April 18 to roughly $17.9 billion within 48 hours, a decline of $8.5 billion.
Across all DeFi protocols, total value locked dropped from $99.5 billion to $86.3 billion — a $13.2 billion wipeout in two days, pushing the sector to a one-year low.
Blame shifts between LayerZero and KelpDAO
The two protocols have clashed publicly over who bears responsibility. LayerZero said the exploit stemmed from Kelp’s configuration: the protocol relied on a single LayerZero DVN (Decentralized Verifier Network) as its sole verification path, a setup LayerZero claims it previously advised against. Kelp fired back, pointing out that LayerZero’s own quickstart guide and default GitHub repository point to exactly that 1/1 DVN configuration — and that roughly 40% of LayerZero-integrated protocols currently operate under the same settings.
A DVN, in this context, is a set of independent verifiers that confirm a cross-chain message is legitimate before a bridge executes it. Using only one verifier creates a single point of failure.
LayerZero subsequently attributed the attack with preliminary confidence to TraderTraitor, a subgroup of North Korea’s Lazarus Group responsible for several of 2025’s largest crypto thefts, including the $1.5 billion Bybit exchange hack. The Arbitrum Security Council said it acted “with input from law enforcement” before executing Monday’s freeze, which does not affect any Arbitrum user funds or applications.
What Aave does next
With up to $230 million in potential bad debt on the table, Aave’s DAO governance is under pressure to respond. Aave’s Safety Module — a pool of AAVE and stablecoin liquidity staked by token holders to cover shortfalls — exists precisely for events like this, but $230 million would be one of the largest calls ever made on the system. An Aave governance proposal to address bad debt distribution is expected imminently. The AAVE token fell roughly 16% in the 48 hours after the exploit, settling near $92 as of Tuesday morning.
The frozen $71 million in Arbitrum remains inaccessible pending further governance action. Recovering the remaining $221 million distributed across 20 chains looks considerably harder. On-chain analysts tracking the exploiter’s wallets have reported the use of privacy tools and cross-chain hops to obscure the fund trail.
A wider infrastructure question
The KelpDAO attack has reignited debate about cross-chain bridge security at a structural level. Four of the five largest DeFi exploits in 2026 have targeted bridge or cross-chain infrastructure rather than smart contract logic in the protocols themselves. Security researchers argue this reflects a maturation in attacker sophistication: application-layer contracts have been audited more rigorously, pushing attackers toward the less-scrutinized verification and relay layers underneath.
LayerZero has said it will release updated documentation recommending multi-DVN configurations for all protocols. Whether existing integrations follow suit depends on governance decisions across dozens of independent protocols — a slow process relative to the speed at which attackers can move.
Frequently asked questions
What is KelpDAO and what does it do?
Kelp DAO is a liquid restaking protocol built on EigenLayer. It lets users deposit ETH to earn restaking rewards and receive rsETH in return — a transferable token representing their staked position. The protocol operates across multiple blockchains using LayerZero’s cross-chain messaging system to move assets between networks.
Can the frozen Arbitrum funds be returned to Kelp DAO victims?
The $71 million frozen by Arbitrum’s Security Council will remain locked until the Arbitrum DAO votes on what to do with it. A recovery process coordinated with Kelp DAO is the most likely outcome, though governance timelines and legal complexity mean resolution could take weeks or months.
Is this the same Lazarus Group behind the Bybit hack in 2025?
LayerZero’s attribution points to TraderTraitor, a Lazarus subgroup that U.S. authorities linked to the $1.5 billion Bybit exchange theft in February 2025. The attribution remains preliminary, but the attack methodology — RPC node compromise combined with cross-chain verification manipulation — is consistent with prior TraderTraitor operations.








