BFM Times
  • News AI
  • Crypto
    • Crypto Currency
    • Crypto Forecast
    • Crypto Tools
    • Crypto Wallets
    • Exchanges
  • Academy
    • Blockchain
    • Crypto Investing
    • DeFi
    • Web3
  • News
  • AI
  • Finance
  • Top List
    • Top Monthly ICOs
    • Top Monthly Presales
    • Best Crypto to Buy Now: Top 10 Picks
    • Best Crypto Exchanges
    • Crypto Wallets with Built-In Exchanges: Top 5 Picks for 2026
  • Influencers
  • Accelerator
  • Tools
    • Market Live
    • Converter
    • Exchanges
    • Treasuries
    • Token Sale
Reading: Infrastructure Under Siege: The $292 Million Kelp DAO Bridge Exploit
Share
Advertise With Us
  • Top Monthly ICOs
  • Top Monthly Presales
  • Best Crypto Exchanges
  • Best Crypto to Buy Now
  • Best Altcoins for Long Term Investment
  • Best Hardware Wallets
Bfm Times
Advertise With Us
  • Crypto
  • Academy
  • News
  • AI
  • Finance
  • Influencers
  • Accelerator
  • News AI
Search
Follow US
  • Home
  • News AI
  • Crypto
  • Academy
  • News
  • AI
  • Finance
  • Top List
  • Accelerator
  • Market Live
  • Converter
  • Exchanges
  • Treasuries
  • Token Sale
© 2026 All Rights Reserved.
BFM Times > News > Infrastructure Under Siege: The $292 Million Kelp DAO Bridge Exploit
NewsTrending

Infrastructure Under Siege: The $292 Million Kelp DAO Bridge Exploit

Jim
Last updated: 27/04/2026 1:59 am
Published: 27/04/2026
Share
Infrastructure Under Siege_ The $292 Million Kelp DAO Bridge Exploit
Infrastructure Under Siege_ The $292 Million Kelp DAO Bridge Exploit
SHARE

Key Insights

  • Loss in USD: 116,500 rsETH (worth $292 million) was stolen on April 18, 2026.
  • Method Used: Hackers attacked the infrastructure – Remote Procedure Call (RPC) nodes.
  • Who is Responsible? The forensic findings indicate that the Lazarus Group from North Korea committed the hack.
  • How did it Happen? The hackers breached the RPC nodes inside the network and carried out a DDoS attack to cause the system to switch to a bad environment.
  • Spread: Money taken was used for collateral in Aave, causing close to $200 million in debts without collateral.
  • Response: The Arbitrum Security Council and SEAL 911 were able to freeze more than 30,000 ETH.

The Phantom Burn: $292M Gone in Minutes

On April 18, 2026, the world of decentralized finance experienced its biggest hack of the year. The attack on Kelp DAO, a top liquid restaking platform, was a poisoning attack that circumvented smart contract security. Rather than exploiting a vulnerability in software that would normally be targeted by a hacker, this attack targeted the “data plumbing” of cross-chain bridges that are used to synchronize blockchain states.

Contents
    • Key Insights
  • The Phantom Burn: $292M Gone in Minutes
  • The 1-of-1 Verifier is not infallible
  • Breaking it down: RPC Spinning and DDoS Timing
  • Phase 1: Node Compromise
  • Phase 2: DDoS and Failover
  • The Ripple Effect: Aave’s Debt Problem
  • Context: Evolution of Infrastructure Exploits
  • Recovery and Future Outlook
  • Frequently Asked Questions
    • What happened in the $292 million Kelp DAO bridge exploit?
    • How was the Kelp DAO bridge exploit possible?

It exploited the Kelp DAO bridge adapter that uses LayerZero messages. An attacker’s address on Ethereum was paid 116,500 rsETH at 17:35 UTC. The release was in response to a message stating tokens had been burned on the source chain, Unichain. No such burn occurred. The bridge contract did what it was meant to do; it received a verified message and paid out money. The problem was that the verification was not done properly.

The 1-of-1 Verifier is not infallible

The issue is with Kelp DAO’s “1-of-1” Decentralized Verifier Network (DVN). This means that only LayerZero Labs was signing instructions. LayerZero allows for a multi-verifier model, but Kelp DAO chose a single verifier. According to security experts, this presented a single point of failure. By directing attention to the data sources used by that verifier, hackers thus produced an echo chamber of misinformation that a multi-DVN system would have likely filtered out.

Breaking it down: RPC Spinning and DDoS Timing

The attack suggests a well-organised threat actor. The hackers didn’t steal keys or look for vulnerabilities in smart contracts. Rather, they conducted a multi-step attack on the data feed of LayerZero’s DVN.

Phase 1: Node Compromise

The attackers accessed the RPC nodes used by the DVN to validate state on the source chain. They took control of two separate internal nodes and replaced the software with spoofing variants. These nodes provided legitimate data for all queries but spoofed burn events for the attacker’s transactions.

Phase 2: DDoS and Failover

Anticipating the DVN would cross-check data with healthy nodes, the hackers initiated a large-scale Distributed Denial of Service (DDoS) attack on external nodes. The DVN’s failover mechanisms kicked in to read from the only two remaining sources: the two corrupted nodes. With the DVN reading only from a poisoned environment, it accepted the false burn and signed the message. This enabled the Ethereum bridge to unlock the $292 million in rsETH.

The Ripple Effect: Aave’s Debt Problem

The effects were not limited to rsETH. Being a liquid restaking token, rsETH is widely used as collateral. The hackers immediately began to milk additional value. The attackers staked the unbacked rsETH (the staked token) into Aave V3 shortly after the tokens were released. The market believed rsETH to be a 1:1 staked Ethereum (ETH) token at the time, and the attacker borrowed about $195 million of Wrapped Ether (WETH) and stablecoins.

This turned tokens that didn’t exist into assets with high liquidity. Aave’s liquidity pools were left with an enormous hole when the contracts were paused. Analysts in the industry estimate that Aave will be left with more than $170 million in bad debt, depending on the price of the remaining rsETH.

Context: Evolution of Infrastructure Exploits

Kelp DAO comes hot on the heels of a $285 million Drift Protocol exploit earlier this month. Cybersecurity companies report changes in Lazarus Group operations. As smart contract audits get better, hackers exploit the infrastructure and RPC providers trusted by protocols.

A “he said, she said” dispute has played out between Kelp DAO and LayerZero. LayerZero claims they recommended a multi-DVN setup. Kelp DAO has claimed they implemented the default quickstart guides in LayerZero’s documentation.

Recovery and Future Outlook

By late April, the Arbitrum Security Council has locked up $75 million in related accounts. SEAL 911 has helped facilitate pauses in ten L2 chains to prevent a further $95 million loss. But monitoring of the blockchain indicates 75,000 ETH has been withdrawn via THORChain, making it unrecoverable.

The attack highlights that DeFi can only be as secure as its most centralised data source. The hack will mean the industry should move away from 1-of-1 verifier systems and towards multi-provider consensus.

Frequently Asked Questions

What happened in the $292 million Kelp DAO bridge exploit?

Attackers reportedly exploited vulnerabilities in the Kelp DAO bridge system, leading to losses worth around $292 million.

How was the Kelp DAO bridge exploit possible?

The breach was allegedly caused by smart contract or bridge security weaknesses that hackers were able to manipulate.

Disclaimer: BFM Times acts as a source of information for knowledge purposes and does not claim to be a financial advisor. Kindly consult your financial advisor before investing.

Tether Strikes “Economic Fury” Blow: $344 Million USDT Frozen in Historic Sanctions Crackdown Against Iran
Consortium of 12 European Banks Operating as Qivalis Ventures to Launch MiCA Compliant Euro Stablecoin in H2, 2026
Kelp DAO Hack Impacts AAVE as it Creates a $260M Net Debt, Daily Margin Requirements at $110k
BlackRock ETF Adds $167 million BTC in a Day as Market Recovers
Bitcoin Beats all Major Asset Classes in the Past Decade
Share This Article
Facebook Email Copy Link Print
Previous Article Qivalis Venture Firebloks to Launch European Stablecoin Consortium of 12 European Banks Operating as Qivalis Ventures to Launch MiCA Compliant Euro Stablecoin in H2, 2026
Next Article Tether Strikes _Economic Fury_ Blow_ $344 Million USDT Frozen in Historic Sanctions Crackdown Against Iran Tether Strikes “Economic Fury” Blow: $344 Million USDT Frozen in Historic Sanctions Crackdown Against Iran
- Advertisement -
Ad image

Latest Posts

What Problem Does Algorand Solve__11zon
What Problem Does Algorand Solve?
FAQ
Vitalik_ Ethereum Is Not for High-Frequency Trading in 2026
Vitalik: Ethereum Is Not for High-Frequency Trading in 2026
News
Does Toncoin have a future
Does Toncoin have a future?
FAQ
Justin Sun Sues Trump-Linked World Liberty Financial Over 75 Million Token Freeze
Justin Sun Sues Trump-Linked World Liberty Financial Over 75 Million Token Freeze
News Trending
- Advertisement -
Ad image

You Might Also Like

BlackRock CEO_ India Leads the World in Digital Finance_11zon
News

BlackRock CEO: India Leads the World in Digital Finance

20/04/2026
MicroStrategy Returns to Profit as Bitcoin Tops $75,577
News

MicroStrategy Returns to Profit as Bitcoin Tops $75,577

18/04/2026
Is Algorand an Ethereum Token
FAQTrending

Is Algorand an Ethereum Token?

18/04/2026
South Korea
News

South Korea Leads Global Crypto With 30% Market Share

17/04/2026

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Facebook X-twitter Instagram Linkedin Reddit Pinterest Telegram Youtube
BFM Times

For the Phenomenal Times

Quick Links

  • About Us
  • Privacy Policy
  • Press Release
  • Partners
  • Submit Your Article on BFM Times
  • Events
  • Work With Us
  • Advertise
  • Jobs
  • Editorial Guidelines
  • Disclaimer
  • Refund and Returns Policy
  • Terms & Conditions
  • Contact Us

Newsletter

You can be the first to find out the latest news and tips about trading, markets...

Please enable JavaScript in your browser to complete this form.
Loading
Ad image

Copyright @ 2026 BFM Times. All Rights Reserved.

© 2026 All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?