An attacker drained 116,500 rsETH from Kelp DAO’s LayerZero-powered cross-chain bridge on April 18, 2026, walking away with roughly $292 million in roughly 46 minutes. The exploit is now the largest DeFi hack of 2026, and its aftermath is still unfolding: Aave is sitting on an estimated $196 million in bad debt, rsETH remains stranded across more than 20 blockchain networks, and LayerZero has preliminarily attributed the attack to North Korea’s Lazarus Group.
A cross-chain bridge is a protocol that locks tokens on one blockchain and issues equivalent tokens on another, letting users move assets between networks. Kelp’s bridge relied on LayerZero’s cross-chain messaging infrastructure to validate these transfers.
Key Takeaways
- Kelp DAO lost 116,500 rsETH (~$292M) on April 18 at 17:35 UTC — the largest DeFi exploit of 2026.
- The root cause was a 1-of-1 DVN (decentralized verifier network) configuration that let attackers fake a valid cross-chain transaction after compromising a single RPC node.
- Aave froze rsETH markets after attackers deposited stolen tokens as collateral and borrowed ~$196M in wrapped ether — leaving the protocol with significant bad debt.
- LayerZero has preliminarily linked the attack to North Korea’s Lazarus Group and says it will no longer process messages from applications running single-verifier setups.
Published: April 20, 2026 — 12:00 UTC
How a single verifier brought down $292 million
The attack began at 17:35 UTC on April 18, when an attacker sent a crafted message to Kelp’s LayerZero bridge. According to LayerZero’s post-incident disclosure published on April 20, Kelp was running a 1-of-1 DVN configuration — a setup where a single verifier node is responsible for confirming cross-chain messages. LayerZero had previously recommended that integrating protocols use multiple independent DVNs, requiring consensus before any transaction could be approved.
A DVN, or decentralized verifier network, is an independent node that confirms the authenticity of cross-chain messages before they are processed. Using only one means a single point of failure: if that node is compromised, the entire system is exposed.
Attackers reportedly compromised two RPC nodes and launched a distributed denial-of-service attack to force a failover, pushing Kelp’s single verifier into accepting a fraudulent transaction. The bridge then released 116,500 rsETH — about 18% of the token’s entire circulating supply — to a wallet funded via Tornado Cash ten hours earlier. No ETH was actually transferred from another chain. The rsETH was, in effect, conjured from nothing.
Kelp’s emergency multisig froze the protocol’s core contracts at 18:21 UTC, 46 minutes after the drain was complete. By then, the attacker had moved.
Aave absorbs the collateral damage
After draining Kelp’s bridge, the attacker deposited the stolen rsETH into Aave V3 and V4 as collateral, then borrowed approximately $196 million in wrapped ether against it. The borrowed ETH, unlike the rsETH used as collateral, is real. Aave’s safety module is now partially on the hook for the shortfall.
Aave’s total value locked dropped from $26.4 billion on April 18 to around $20 billion by Sunday morning, a decline of roughly $6.4 billion. The AAVE token fell approximately 16% in the 24 hours following the exploit. Emergency market freezes hit Aave, SparkLend, Fluid, and Upshift, all of which had accepted rsETH as collateral or provided liquidity against it.
The Aave DAO is now reviewing its risk parameters for liquid restaking tokens. Aave’s safety module holds about $500 million in AAVE and stablecoins available to cover bad debt, but covering $196 million would require a significant portion of that reserve and likely trigger an aDAO governance vote to recapitalize.
What Lazarus Group’s involvement means
In its disclosure, LayerZero wrote that “preliminary indicators suggest attribution to a highly-sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor.” The company noted it does not yet have direct private-key or infrastructure evidence, and independent analysts have not corroborated the attribution.
If confirmed, this would be among Lazarus Group’s largest single operations. The group has been linked to more than $1.5 billion in crypto theft since 2017, including the $625 million Ronin bridge hack in 2022. The US Treasury’s OFAC has sanctioned Tornado Cash, the mixer the attacker used to fund the exploit wallet, making any confirmed Lazarus attribution likely to trigger additional regulatory scrutiny of DeFi bridge infrastructure.
LayerZero said it has confirmed zero contagion to other applications on its network that ran multi-verifier configurations. Going forward, the company says it will refuse to sign messages for any application using a 1-of-1 setup.
Where this leaves DeFi bridge security
Cross-chain bridges have been the single most exploited category in DeFi for three consecutive years. According to Hacken’s Q1 2026 report, Web3 projects lost $464.5 million in bridge and infrastructure attacks in the first quarter alone — before the Kelp incident. Saturday’s hack adds another $292 million to that tally.
The Kelp exploit follows a consistent pattern: a protocol builds on a cross-chain messaging layer with weaker-than-recommended settings, creating a configuration gap that sophisticated attackers can target. The technical flaw was not in LayerZero’s code but in how Kelp deployed it. That distinction matters for the broader industry: even sound infrastructure can be made dangerous by poor integration choices.
Frequently asked questions
What is rsETH and why was it used as collateral?
rsETH is Kelp DAO’s liquid restaking token. Users deposit ETH into EigenLayer through Kelp and receive rsETH in return, which they can use across DeFi protocols. Aave accepted rsETH as collateral because it was backed by real staked ETH — until the bridge hack created 116,500 rsETH with no actual backing.
Will Aave users lose money?
Aave’s safety module is designed to absorb bad debt through a reserve fund. The $196 million shortfall is significant but likely manageable through a governance vote to use safety module funds. Individual Aave depositors are not automatically liable, though a large safety module draw would dilute AAVE token holders through a potential shortfall auction.
What happens to rsETH holders on layer 2 networks?
Because Kelp’s bridge held reserves backing rsETH across more than 20 networks, those tokens are now partially unbacked. Kelp has frozen the protocol and not announced a recovery plan. Holders on layer 2s currently cannot withdraw or redeem, and the value of their rsETH depends on what Kelp can recover from the attacker or compensate through its treasury.








