BFM Times
  • News AI
  • Crypto
    • Crypto Currency
    • Crypto Forecast
    • Crypto Tools
    • Crypto Wallets
    • Exchanges
  • Academy
    • Blockchain
    • Crypto Investing
    • DeFi
    • Web3
  • News
  • Finance
  • Top List
    • Top Monthly ICOs
    • Top Monthly Presales
    • Best Crypto to Buy Now in 2026: Top Picks for Smart Investors
    • Best Crypto Exchanges
    • Crypto Wallets with Built-In Exchanges: Top 5 Picks for 2026
  • Influencers
  • Accelerator
  • Tools
    • Market Live
    • Converter
    • Exchanges
    • Treasuries
    • Token Sale
Reading: Infrastructure Under Siege: The $292 Million Kelp DAO Bridge Exploit
Share
Advertise With Us
  • Top Monthly ICOs
  • Top Monthly Presales
  • Best Crypto Exchanges
  • Best Crypto to Buy Now
  • Best Altcoins for Long Term Investment
  • Best Hardware Wallets
Bfm Times
Advertise With Us
  • Crypto
  • Academy
  • News
  • Finance
  • Influencers
  • Accelerator
  • News AI
Search
Follow US
  • Home
  • News AI
  • Crypto
  • Academy
  • News
  • Finance
  • Top List
  • Accelerator
  • Market Live
  • Converter
  • Exchanges
  • Treasuries
  • Token Sale
© 2026 All Rights Reserved.
BFM Times > News > Infrastructure Under Siege: The $292 Million Kelp DAO Bridge Exploit
NewsTrending

Infrastructure Under Siege: The $292 Million Kelp DAO Bridge Exploit

Jim
Last updated: 14/05/2026 7:04 am
Published: 27/04/2026
Share
Infrastructure Under Siege_ The $292 Million Kelp DAO Bridge Exploit
Infrastructure Under Siege_ The $292 Million Kelp DAO Bridge Exploit
SHARE

Key Insights

  • Loss in USD: 116,500 rsETH (worth $292 million) was stolen on April 18, 2026.
  • Method Used: Hackers attacked the infrastructure – Remote Procedure Call (RPC) nodes.
  • Who is Responsible? The forensic findings indicate that the Lazarus Group from North Korea committed the hack.
  • How did it Happen? The hackers breached the RPC nodes inside the network and carried out a DDoS attack to cause the system to switch to a bad environment.
  • Spread: Money taken was used for collateral in Aave, causing close to $200 million in debts without collateral.
  • Response: The Arbitrum Security Council and SEAL 911 were able to freeze more than 30,000 ETH.

The Phantom Burn: $292M Gone in Minutes

On April 18, 2026, the world of decentralized finance experienced its biggest hack of the year. The attack on Kelp DAO, a top liquid restaking platform, was a poisoning attack that circumvented smart contract security. Rather than exploiting a vulnerability in software that would normally be targeted by a hacker, this attack targeted the “data plumbing” of cross-chain bridges that are used to synchronize blockchain states.

Contents
    • Key Insights
  • The Phantom Burn: $292M Gone in Minutes
  • The 1-of-1 Verifier is not infallible
  • Breaking it down: RPC Spinning and DDoS Timing
  • Phase 1: Node Compromise
  • Phase 2: DDoS and Failover
  • The Ripple Effect: Aave’s Debt Problem
  • Context: Evolution of Infrastructure Exploits
  • Recovery and Future Outlook
  • Frequently Asked Questions
    • What happened in the $292 million Kelp DAO bridge exploit?
    • How was the Kelp DAO bridge exploit possible?

It exploited the Kelp DAO bridge adapter that uses LayerZero messages. An attacker’s address on Ethereum was paid 116,500 rsETH at 17:35 UTC. The release was in response to a message stating tokens had been burned on the source chain, Unichain. No such burn occurred. The bridge contract did what it was meant to do; it received a verified message and paid out money. The problem was that the verification was not done properly.

The 1-of-1 Verifier is not infallible

The issue is with Kelp DAO’s “1-of-1” Decentralized Verifier Network (DVN). This means that only LayerZero Labs was signing instructions. LayerZero allows for a multi-verifier model, but Kelp DAO chose a single verifier. According to security experts, this presented a single point of failure. By directing attention to the data sources used by that verifier, hackers thus produced an echo chamber of misinformation that a multi-DVN system would have likely filtered out.

Breaking it down: RPC Spinning and DDoS Timing

The attack suggests a well-organised threat actor. The hackers didn’t steal keys or look for vulnerabilities in smart contracts. Rather, they conducted a multi-step attack on the data feed of LayerZero’s DVN.

Phase 1: Node Compromise

The attackers accessed the RPC nodes used by the DVN to validate state on the source chain. They took control of two separate internal nodes and replaced the software with spoofing variants. These nodes provided legitimate data for all queries but spoofed burn events for the attacker’s transactions.

Phase 2: DDoS and Failover

Anticipating the DVN would cross-check data with healthy nodes, the hackers initiated a large-scale Distributed Denial of Service (DDoS) attack on external nodes. The DVN’s failover mechanisms kicked in to read from the only two remaining sources: the two corrupted nodes. With the DVN reading only from a poisoned environment, it accepted the false burn and signed the message. This enabled the Ethereum bridge to unlock the $292 million in rsETH.

The Ripple Effect: Aave’s Debt Problem

The effects were not limited to rsETH. Being a liquid restaking token, rsETH is widely used as collateral. The hackers immediately began to milk additional value. The attackers staked the unbacked rsETH (the staked token) into Aave V3 shortly after the tokens were released. The market believed rsETH to be a 1:1 staked Ethereum (ETH) token at the time, and the attacker borrowed about $195 million of Wrapped Ether (WETH) and stablecoins.

This turned tokens that didn’t exist into assets with high liquidity. Aave’s liquidity pools were left with an enormous hole when the contracts were paused. Analysts in the industry estimate that Aave will be left with more than $170 million in bad debt, depending on the price of the remaining rsETH.

Context: Evolution of Infrastructure Exploits

Kelp DAO comes hot on the heels of a $285 million Drift Protocol exploit earlier this month. Cybersecurity companies report changes in Lazarus Group operations. As smart contract audits get better, hackers exploit the infrastructure and RPC providers trusted by protocols.

A “he said, she said” dispute has played out between Kelp DAO and LayerZero. LayerZero claims they recommended a multi-DVN setup. Kelp DAO has claimed they implemented the default quickstart guides in LayerZero’s documentation.

Recovery and Future Outlook

By late April, the Arbitrum Security Council has locked up $75 million in related accounts. SEAL 911 has helped facilitate pauses in ten L2 chains to prevent a further $95 million loss. But monitoring of the blockchain indicates 75,000 ETH has been withdrawn via THORChain, making it unrecoverable.

The attack highlights that DeFi can only be as secure as its most centralised data source. The hack will mean the industry should move away from 1-of-1 verifier systems and towards multi-provider consensus.

Frequently Asked Questions

What happened in the $292 million Kelp DAO bridge exploit?

Attackers reportedly exploited vulnerabilities in the Kelp DAO bridge system, leading to losses worth around $292 million.

How was the Kelp DAO bridge exploit possible?

The breach was allegedly caused by smart contract or bridge security weaknesses that hackers were able to manipulate.

Disclaimer: BFM Times acts as a source of information for knowledge purposes and does not claim to be a financial advisor. Kindly consult your financial advisor before investing.

Michael Saylor Makes Controversial Remarks on his 32 BTC Sale, Says He Never Said Company Wouldn’t Sell
Have Crypto Markets Formed a Bottom Yet? Standard Chartered Agrees, Critical Factors Deny
Will The Current Recovery Last in Crypto Markets?
ZCash (ZEC) Crashes 60% from $603 to $244 in a Single Day amid Bug Discovery
SUI Brings Upgraded Blockchain Privacy to Its Chain
Share This Article
Facebook Email Copy Link Print
Previous Article Qivalis Venture Firebloks to Launch European Stablecoin Consortium of 12 European Banks Operating as Qivalis Ventures to Launch MiCA Compliant Euro Stablecoin in H2, 2026
Next Article Tether Strikes _Economic Fury_ Blow_ $344 Million USDT Frozen in Historic Sanctions Crackdown Against Iran Tether Strikes “Economic Fury” Blow: $344 Million USDT Frozen in Historic Sanctions Crackdown Against Iran
- Advertisement -
Ad image

Latest Posts

exhibitionday1405
Indonesia Blockchain Week 2026: From Web3 Experimentation to Real-World Impact
Press Release
London-iGaming-RegCom-2026
1 Month Until London iGaming RegCom 2026 Opens with Insightful Industry Discussions
Press Release
DBW 26
Amsterdam set to welcome thousands of Digital Assetprofessionals as Dutch Blockchain Week 2026 reveals theprogram
Press Release
Canada-Crypto-Week
Canada Crypto Week Returns July 20–26, Celebrating the Future of Web3, Digital Assets and AI
Press Release
- Advertisement -
Ad image

You Might Also Like

Bitcoin Crashing Today
Trending

Why is Bitcoin Down Today?

02/06/2026
When This Metric Starts Moving, Bitcoin Price
Trending

Citibank Predicts Bitcoin will Hit $189k in 2026

01/06/2026
Tether Launches "Official Lari Stablecoin" in Georgia
Trending

Tether Launches “Official Stablecoin” in Georgia with Government Partnership

30/05/2026
Rare Moment SEC Commissioner Upholds Crypto Privacy, Asks Regulators to Stop Seeing Them with Suspicion
Trending

Rare Moment: SEC Commissioner Upholds Crypto Privacy, Asks Regulators to Stop Seeing Them with Suspicion

28/05/2026

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Facebook X-twitter Instagram Linkedin Reddit Pinterest Telegram Youtube
BFM Times

For the Phenomenal Times

Quick Links

  • About Us
  • Privacy Policy
  • Press Release
  • Partners
  • Submit Your Article on BFM Times
  • Events
  • Work With Us
  • Advertise
  • Editorial Guidelines
  • Disclaimer
  • Refund and Returns Policy
  • Terms & Conditions
  • Contact Us

Newsletter

You can be the first to find out the latest news and tips about trading, markets...

Please enable JavaScript in your browser to complete this form.
Loading
Ad image

Copyright @ 2026 BFM Times. All Rights Reserved.

© 2026 All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?