🚨 Kelp DAO hit by massive $292M LayerZero bridge exploit 🚨
Kelp DAO has suffered one of the largest DeFi hacks of 2026, after attackers exploited its rsETH cross-chain bridge—draining hundreds of millions and shaking confidence in cross-chain infrastructure.
🔑 Key points
🔹 $292M drained: Attackers stole ~116,500 rsETH, about 18% of total supply.
🔹 Bridge vulnerability: The exploit targeted a LayerZero-based messaging system, allowing a forged cross-chain transaction.
🔹 Single-point failure: The system relied on a 1-validator setup, making it easier to spoof approvals.
🔹 Funds leveraged, not dumped: Instead of selling, the attacker used stolen rsETH as collateral on lending platforms like Aave to borrow ETH.
🔹 Protocol fallout: Multiple DeFi platforms froze rsETH markets to prevent further contagion.
🔎 Why it matters
🔹 Bridge risk exposed: Cross-chain bridges remain one of the weakest points in crypto infrastructure.
🔹 Systemic contagion: The hack didn’t stay isolated—it spread risk into lending markets, creating potential bad debt.
🔹 DeFi composability danger: One exploit cascaded across multiple protocols due to interconnected systems.
🔹 Security design lesson: Reliance on minimal validation (1-of-1 verifier) highlights critical flaws in some deployments.
🔹 Market confidence hit: Events like this can slow institutional adoption—especially in complex DeFi primitives.
🎯 Bottom line: This wasn’t just a hack—it was a structural failure in cross-chain security design. The Kelp DAO exploit shows how a single weak link can ripple across DeFi, reinforcing that scalability without robust security can come at a massive cost.
https://www.theblock.co/post/397988/kelp-daos-rseth-bridge-apparently-exploited-for-roughly-292-million-in-layerzero-based-attack