A coalition of decentralized finance protocols has committed more than 43,500 ETH — worth over $101 million — to restore rsETH’s backing after a April 18 exploit drained $292 million from KelpDAO’s cross-chain bridge. The initiative, called “DeFi United,” was proposed by Aave service providers on April 23 and has drawn contributions from Lido Finance, EtherFi, Golem Foundation, and Frax Finance, alongside a personal pledge of 5,000 ETH from Aave founder Stani Kulechov. Aave, the largest DeFi lending platform, faces up to $230 million in bad debt from the attack.

rsETH is a liquid restaking token issued by KelpDAO that represents staked Ether, allowing holders to earn staking rewards while using the token as collateral in DeFi lending markets.

Key Takeaways

  • An attacker exploited KelpDAO’s LayerZero bridge on April 18 to mint 116,500 unbacked rsETH tokens worth approximately $292 million — the largest DeFi exploit of 2026.
  • The attacker deposited ~90,000 fake rsETH into Aave as collateral and borrowed roughly $190 million in ETH and other assets, leaving Aave with $123–230 million in potential bad debt.
  • DeFi protocols including Aave, Lido, EtherFi, Mantle, and Golem Foundation have pledged over 43,500 ETH ($101M+) through the DeFi United initiative to cover the rsETH deficit.
  • DeFi total value locked fell more than $13 billion in two days following the exploit, reflecting panic withdrawals across the sector.

Published: April 24, 2026 — midday UTC

How the KelpDAO exploit unfolded

On April 18, an attacker exploited a configuration flaw in KelpDAO’s LayerZero-powered omnichain bridge, gaining the ability to mint tokens out of thin air. Blockchain analysts have linked the attack to North Korea’s Lazarus Group, though attribution is still being confirmed.

KelpDAO’s bridge used a single-verifier configuration — meaning only one entity needed to approve cross-chain messages. That setup let the attacker forge a valid-looking instruction, tricking the bridge into releasing 116,500 rsETH from KelpDAO’s Ethereum mainnet escrow to an attacker-controlled address. None of those tokens were backed by real ETH.

The attacker then moved fast. Nearly 90,000 of the fraudulent rsETH tokens were deposited into Aave as collateral across Ethereum and Arbitrum, and approximately $190 million in ETH and other assets was borrowed against them. When the fake collateral was identified, rsETH’s price collapsed. Aave was left holding positions that had no real backing.

An incident report commissioned by Aave’s service providers found two scenarios for total losses. If damage is distributed across all rsETH holders globally, Aave’s exposure falls to around $123 million. If losses are contained to Aave’s Layer 2 markets only, the figure rises to $230 million.

DeFi United: the industry response

Within five days of the exploit, Aave’s service providers assembled a recovery coalition. The DeFi United initiative, announced April 23, aims to raise enough ETH to fully restore rsETH’s backing — meaning every rsETH token in circulation would again represent real, staked Ether.

Pledges confirmed as of April 24 include:

  • Stani Kulechov (Aave founder): 5,000 ETH personal contribution
  • EtherFi Foundation: 5,000 ETH
  • Lido Labs: proposed 2,500 stETH (~$5.8 million) via a DAO governance vote
  • Golem Foundation: 1,000 ETH
  • Mantle: proposed a 30,000 ETH loan (pending governance approval)
  • Frax Finance: working on a contribution, amount not yet disclosed

A live tracker at defiunited.fyi shows current commitments. The Mantle loan proposal alone would cover most of the gap, but it requires a full DAO governance vote before funds can move.

The total TVL across DeFi dropped more than $13 billion in the two days after the exploit — a reflection of how quickly confidence drains when a major protocol is compromised. The speed of the DeFi United response is an attempt to reverse that.

The single-verifier flaw that made this possible

LayerZero is a cross-chain messaging protocol that lets separate blockchains communicate and coordinate. KelpDAO used LayerZero to run the bridge for its omnichain fungible token — the standard that allows rsETH to exist on multiple chains from a single backing pool on Ethereum.

The exploit did not come from a bug in LayerZero’s own code. It came from how KelpDAO configured it. LayerZero allows bridge operators to choose how many independent verifiers must sign off on a cross-chain message before it executes. KelpDAO chose one. LayerZero’s published security guidelines recommend multiple independent verifiers for bridges controlling large amounts of value.

That single point of trust is what the attacker compromised. Once one verifier was spoofed, the bridge had no mechanism to detect the fraudulent instruction. The Ethereum escrow released the tokens, and the attack was complete in minutes.

Cross-chain bridges remain one of DeFi’s most persistent attack surfaces. According to Hacken’s Q1 2026 security report, Web3 projects lost $482 million in Q1 2026, with infrastructure and access control failures — not smart contract bugs — driving the majority of losses.

What happens next

Three things have to go right for DeFi United to succeed. First, Mantle’s 30,000 ETH loan proposal needs to pass governance, which typically takes several days. Second, smaller pledged contributions need to be confirmed and delivered. Third, KelpDAO needs to resume normal operations with a patched bridge configuration, or face permanent user flight to competitor restaking protocols like EigenLayer and Symbiotic.

Aave itself is under pressure. The protocol’s governance community is debating whether to tighten collateral requirements for newer liquid staking and restaking tokens, or to require multi-chain risk assessments before any new collateral type is accepted. Either change would reduce the protocol’s exposure to future cross-chain exploits — but would also shrink the range of assets users can borrow against.

For KelpDAO, the path forward is narrower. The protocol holds over $1 billion in TVL across restaked assets, but trust in its bridge architecture is gone. Whether the DeFi United coalition covers the hole or not, users who moved funds to KelpDAO for higher yields will reconsider that trade-off.


Frequently Asked Questions

What is rsETH and why did Aave accept it as collateral?

rsETH is a liquid restaking token issued by KelpDAO. It lets users earn staking rewards on their ETH while using the token in DeFi protocols. Aave accepted rsETH as collateral because it had verified backing and yield characteristics similar to other liquid staking tokens like stETH — before the exploit revealed a critical bridge vulnerability in the issuance mechanism.

Will Aave depositors lose money from this exploit?

If the DeFi United coalition raises enough ETH to cover the deficit, Aave depositors should be protected. The Mantle loan proposal alone covers 30,000 ETH of the ~43,500 ETH already pledged. The risk is governance delay — if the Mantle DAO vote stalls, the timeline for full recovery extends.

Is LayerZero at fault for the KelpDAO exploit?

Security researchers have attributed the exploit to KelpDAO’s own bridge configuration, not a flaw in LayerZero’s code. KelpDAO used a single-verifier setup that LayerZero’s own guidelines advise against for high-value bridges. LayerZero’s protocol itself was not compromised.