Start now →

The Protocol: Kelp DAO exploited for $292 million

By Margaux Nijkerk · Published April 22, 2026 · 10 min read · Source: CoinDesk
DeFiWeb3Security
TechShare this articleX (Twitter)LinkedInFacebookEmail

The Protocol: Kelp DAO exploited for $292 million

Also: DPRK hacking crypto, Aave contagion and Coinbase on quantum computing.

By Margaux Nijkerk|Edited by Nikhilesh De Apr 22, 2026, 4:22 p.m. Make preferred on
Silhouette image of a hooded figure behind three screens.  (geralt/Pixabay)

What to know:

Welcome to The Protocol, CoinDesk's weekly wrap of the most important stories in cryptocurrency tech development. I’m Margaux Nijkerk, a reporter at CoinDesk.

In this issue:

Network News

KELP DAO EXPLOIT: A cross-chain bridge holding nearly a fifth of a restaked ether token's circulating supply just got drained, and the fallout is moving through DeFi faster than Kelp DAO can pause contracts. An attacker drained 116,500 rsETH (restaked ether) from Kelp DAO's LayerZero-powered bridge at 17:35 UTC over the weekend, worth roughly $292 million at current prices and representing about 18% of rsETH's 630,000 token circulating supply tracked by CoinGecko. LayerZero is a cross-chain messaging layer, or the infrastructure that lets different blockchains send verified instructions to each other. Kelp DAO is a liquid restaking protocol, which takes user-deposited ETH, routes it through EigenLayer to earn additional yield on top of standard Ethereum staking rewards, and issues rsETH as a tradeable receipt. The bridge that was drained held the rsETH reserve backing wrapped versions of the token deployed on more than 20 other blockchains. The attacker tricked LayerZero's cross-chain messaging layer into believing a valid instruction had arrived from another network, which triggered Kelp's bridge to release 116,500 rsETH to an attacker-controlled address. Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, at 18:21 UTC. Two follow-up attempts at 18:26 UTC and 18:28 UTC both reverted, each carrying the same LayerZero packet attempting another 40,000 rsETH drain worth roughly $100 million. — Shaurya Malwa Read more.

NORTH KOREA CRYPTO HEIST PLAYBOOK: Less than three weeks after North Korea-linked hackers used social engineering to hit crypto trading firm Drift, hackers tied to the nation appear to have pulled off another major exploit with Kelp. The attack on Kelp, a restaking protocol tied into LayerZero’s cross-chain infrastructure, suggests an evolution in how North Korea-linked hackers operate, not just looking for bugs or stolen credentials, but exploiting the basic assumptions built into decentralized systems. Taken together, the two incidents point to something more organized than a string of one-off hacks, as North Korea continues to escalate its efforts to hijack funds from the crypto sector. “This is not a series of incidents; it is a cadence,” said Alexander Urbelis, chief information security officer and general counsel at ENS Labs. “You cannot patch your way out of a procurement schedule.” More than $500 million was siphoned across the Drift and Kelp exploits in just over two weeks. At its core, the Kelp exploit did not involve breaking encryption or cracking keys. The system actually worked the way it was designed to. Rather, attackers manipulated the data feeding into the system and forced it to rely on those compromised inputs, causing it to approve transactions that never actually occurred. — Margaux Nijkerk Read more.

AAVE AFFECTED BY KELP DAO HACK: An attacker exploited that setup by forging a transfer message that appeared valid. The system approved the transfer even though the tokens were never taken out of the sending chain, meaning new tokens were effectively created without backing, releasing 116,500 rsETH from the Ethereum-side bridge. Rather than selling the assets on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed roughly $190 million in ETH and related assets across Ethereum and Arbitrum, according to the report. This left Aave exposed to collateral whose backing may be significantly impaired. Aave Labs said it moved quickly to contain the risk. Within hours, the protocol froze rsETH markets across its deployments, set loan-to-value ratios to zero, and halted new borrowing against the asset. The outcome now depends largely on how Kelp handles the shortfall. If losses are spread across all rsETH holders, the token would face an estimated 15% depegging (meaning the value of the staked tokens would not match the value of actual ETH), resulting in about $124 million in bad debt for Aave. If losses are instead isolated to Layer 2 networks, the impact would be far more severe, with bad debt rising to roughly $230 million and concentrated on networks such as Arbitrum and Mantle.— Margaux Nijkerk Read more.

COINBASE COMMISSIONS PAPER ON QUANTUM COMPUTING RISKS: A new report commissioned by Coinbase sounds a cautious, but urgent, alarm: Quantum computing won't break crypto tomorrow, but the industry can’t afford to wait. The 50-page paper, authored by an independent advisory board that includes prominent cryptographers and academics like Dan Boneh of Stanford University, Justin Drake of the Ethereum Foundation and Sreeram Kannan of Eigen Labs, concludes that while today’s blockchains remain secure, a future “fault-tolerant quantum computer” capable of breaking widely used encryption is increasingly plausible, and preparation must begin now. In recent months, concerns around quantum risk have moved further into the mainstream. Google researchers have published estimates suggesting that a sufficiently advanced quantum computer could one day break Bitcoin’s cryptography. Major crypto ecosystems have already started mapping out their responses. The Ethereum Foundation has proposed new types of digital signatures that are designed to be safe against quantum computers, while Solana and others are experimenting with quantum-resistant wallet designs. The report stresses that current quantum machines are far from powerful enough to crack the cryptography underpinning Bitcoin, Ethereum and other networks. Breaking standard encryption would require vast computational overhead, a milestone still considered a major engineering challenge. — Margaux Nijkerk Read more.


In Other News


Regulatory and Policy


Calendar

NewslettersHackEthereum News

More For You

The $292 million Kelp DAO exploit shows why crypto bridges are still one of the industry's weakest links

By Margaux Nijkerk|Edited by Nikhilesh De58 minutes ago
lock-broken

The problem is structural and as long as bridges depend on complex systems with shared infrastructure and hidden trust assumptions, they will remain vulnerable.

What to know:

Read full storyLatest Crypto News U.S. Treasury Department in Washington, D.C. (Jesse Hamilton/CoinDesk)

Banks seek to slow down implementation of crypto's GENIUS Act on stablecoin oversight

37 minutes ago
CoinDesk

Crypto Long & Short: Protecting the people building DeFi infrastructure

56 minutes ago
lock-broken

The $292 million Kelp DAO exploit shows why crypto bridges are still one of the industry's weakest links

58 minutes ago
An engineer works with bitcoin mining rigs (Shutterstock)

Trump-linked American Bitcoin shares spike over 12% after announcing more mining power

1 hour ago
CoinDesk

Bitcoin breaks Strategy's STRC ex-dividend date slump for the first time in six months

1 hour ago
Bitcoin (BTC) price on April 22 Wednesday (CoinDesk)

Bitcoin tops $79,000 as crypto rally gathers steam; Circle, Coinbase, Strategy lead

1 hour ago
Top StoriesThe cuts came in the third quarter. (Danny Nelson/CoinDesk)

Crypto giant GSR launches its first ETF to give investors an easy way to bet on the big 3 tokens

2 hours ago
Calculator next to tax documentation (Kelly Sikkema/Unsplash)

Kraken filed 56 million crypto tax forms for 2025. One-third were below $1

4 hours ago
World Liberty Financial's Zak Folkman (Right) at Consensus Hong Kong on Feb. 19. (Nikhilesh De/CoinDesk)

Tron's Justin Sun sues Trump-linked World Liberty Financial over frozen assets

11 hours ago
Hacker facing screens with lines of code (Boitumelo/Unsplash)

Another DeFi protocol loses millions in hack days after KelpDAO breach

9 hours ago
BTC/USD (CoinDesk Data)

Bitcoin tests $78,000 resistance as short-squeeze risks mount, altcoins rally

6 hours ago
True Market Mean (CheckonChain)

A make or break moment: why $79,200 could act as a launchpad or a ceiling for bitcoin

8 hours ago
This article was originally published on CoinDesk and is republished here under RSS syndication for informational purposes. All rights and intellectual property remain with the original author. If you are the author and wish to have this article removed, please contact us at [email protected].

NexaPay — Accept Card Payments, Receive Crypto

No KYC · Instant Settlement · Visa, Mastercard, Apple Pay, Google Pay

Get Started →