Kelp DAO hack — April 2026
Incident facts
| Date of incident | |
|---|---|
| Target type | Cross-chain bridge |
| Loss | $292,000,000Published estimates range $290,000,000 to $292,000,000Price at time of incident |
| Method | Infrastructure compromisecompromised RPC nodes feeding a 1-of-1 LayerZero DVN, which attested to a forged cross-chain message |
| Chains | Ethereum, Unichain, Arbitrum, Base, Multiple chains |
| Attributed to | DPRK Lazarus Group, TraderTraitor sub-groupSuspected |
| Outcome | Users reimbursed |
What happened
At 17:35 UTC on 18 April 2026, in Ethereum block 24,908,285, an attacker drained 116,500 rsETH from the LayerZero OFT adapter backing Kelp DAO's liquid restaking token, roughly $292 million and about 18 per cent of the token's circulating supply. The adapter's balance fell from 116,723 rsETH to 223.
No smart contract bug was involved. Kelp's Unichain-to-Ethereum route ran a 1-of-1 Decentralized Verifier Network with LayerZero Labs as the sole verifier. Per LayerZero's incident statement, the attacker obtained the list of RPC nodes the DVN queried, compromised two of them by swapping the binaries on op-geth nodes, and ran denial-of-service attacks against the remaining providers so the DVN failed over to the poisoned nodes. Those nodes reported a burn that never happened; Unichain's outbound nonce stayed at 307 while Ethereum accepted nonce 308, and the adapter released the escrowed rsETH. Two further attempts minutes later reverted.
The attacker supplied 89,567 rsETH to Aave and borrowed roughly 82,650 WETH and 821 wstETH against it before markets froze. Aave's Guardian froze rsETH across eleven V3 markets within about ninety minutes.
Kelp and LayerZero disputed responsibility in public. Kelp said the 1-of-1 configuration followed LayerZero's documented defaults; LayerZero said Kelp had deployed a single point of failure in production. In May LayerZero conceded it 'made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions'.
Backing was restored through DeFi United, an Aave-led coalition that raised over $300 million in ETH; 117,132 rsETH was refilled into the adapter and rsETH operations resumed.
Law enforcement
LayerZero said it was cooperating with law enforcement and attributed the operation to DPRK's Lazarus Group, specifically the TraderTraitor sub-group; Chainalysis reported that attribution rested on infrastructure analysis and law enforcement coordination. No government indictment, sanctions designation or arrest tied to this incident had been announced as of this research. Separately, terrorism creditors filed a restraining order on 1 May 2026 over assets recovered from the attacker, and Aave was barred from moving roughly $72 million in ETH frozen on Arbitrum pending court approval.
Sources
- LayerZero LabsPrimary · retrieved 2026-08-01
- Aave governance forumPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- ChainalysisSecondary · retrieved 2026-08-01
- Nexus MutualSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
Official post-mortem: https://layerzero.network/blog/kelpdao-incident-statement
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Kelp DAO hack — April 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kelp-daohttps://itokenly.com/hacks/kelp-daoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.