h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Too Connected to Fail: Inside the $292M KelpDAO Bridge Rescue

The largest DeFi hack of 2026 drained $292 million from KelpDAO's bridge. It ended not with a lone backstop or a bounty, but with rival protocols pooling 100,000 ETH to rebuild it.

Bitcoin was trading near $84,000 on Thursday and Ether around $2,640, both easing back from eight-month highs as traders raised their bets on another Federal Reserve rate hike; crypto had already rallied hard after the Fed pushed rates to 4 percent earlier in the month, per market data. But the figure worth holding onto, for anyone who moved money across a cross-chain bridge this year, is not a price. It is roughly 100,000: the number of ETH that a group of rival DeFi protocols pooled together to make the victims of 2026’s largest decentralized-finance hack whole again.

On 18 April 2026, attackers drained about 116,500 rsETH, worth roughly $292 million at the time, out of KelpDAO’s cross-chain bridge, according to a forensic reconstruction by Chainalysis. Most bridge coverage, a lot of ours included, has focused on how the money leaves. This one is worth revisiting for the opposite reason: how some of it came back. The KelpDAO episode produced something the industry had not really seen at this scale, a coordinated on-chain rescue funded not by one deep-pocketed backer and not by a polite negotiation with the thief, but by more than a dozen competing protocols, DAOs, and founders who concluded that letting rsETH collapse would cost all of them more than fixing it.

It also introduced an uncomfortable idea to DeFi, one that has haunted traditional banking for decades: too connected to fail. This is the anatomy of that rescue, and of what it does and does not prove about whether crypto can save itself.

The Hack That Never Touched the Code

Start with what did not happen. No Solidity bug was exploited. No engineer was tricked into signing a malicious transaction. The KelpDAO attackers went after the plumbing that a bridge trusts to tell it the truth.

rsETH is Kelp’s liquid restaking token. To move it between Ethereum and various layer 2 networks, Kelp used a LayerZero bridge adapter that leaned on a single Decentralized Verifier Network, or DVN, to confirm cross-chain messages. Chainalysis put the design flaw plainly: the deployment ran on a 1-of-1 DVN, so, in its words, no second DVN had to agree. One verifier vouching for a message was enough to release tokens.

The attackers, whom LayerZero attributed to North Korea’s Lazarus Group and its TraderTraitor sub-unit, did not need to break that verifier’s cryptography. They fed it lies. According to Chainalysis, they compromised two internal RPC nodes that LayerZero ran across separate clusters, swapped the running software so the nodes served forged blockchain data, and at the same time hit an external RPC provider with a denial-of-service attack. With the honest external path knocked offline, the DVN fell back to the poisoned internal nodes, which reported that rsETH had been burned on Unichain when no such burn had happened. The bridge, believing the burn was real, dutifully released 116,500 rsETH on Ethereum. The malicious node software then self-destructed, wiping its binaries and logs behind it.

Ben Fisch, chief executive of Espresso Systems, described the whole class of failure in one line when he told CoinDesk after the hack: “The bridge worked as designed. It just believed the wrong information.” Most bridges, he added, do not really verify what happened on another chain; they rely on a smaller system to report it, and that smaller system is the target.

It could have been worse. When Kelp’s monitoring flagged the anomaly, the team paused its contracts, blocking a follow-up attempt to mint a further 40,000 rsETH, about $95 million more. The Arbitrum Security Council froze 30,766 ETH of attacker funds within hours. That combination of a working kill switch and a fast freeze, the same off-switch debate we covered in crypto’s reckoning over pause buttons, is the only reason the hole stopped near $292 million rather than closer to $390 million.

The pattern is now the rule, not the exception. TRM Labs found that in the first half of 2026, infrastructure, key, and operational compromises made up roughly 15 percent of hack incidents but around 76 percent of the value stolen, per its H1 2026 report. Bridges are where that math turns most brutal: a contract can pass every audit and still hand over the vault because something it trusted lied to it. In this case the audited contracts behaved exactly as written, and $292 million still left the building.

What rsETH Was Doing There in the First Place

To understand why one bridge failure nearly took down unrelated lending markets, you have to understand what rsETH is and where it had wandered. rsETH is a liquid restaking token. A user deposits ETH or a liquid staking token such as stETH with Kelp, which restakes it to help secure additional networks, and hands back rsETH as a receipt that quietly accrues both staking and restaking yield.

The whole point of a liquid receipt is that it does not sit still. rsETH holders deposited it into Aave and Compound as collateral, borrowed stablecoins against it, frequently looped the position to amplify yield, and bridged it to layer 2 networks where the same cycle repeated. Every hop treated rsETH as money that was as good as the ETH behind it. That assumption holds right up until the ETH behind it is not there anymore.

This is the mechanism NYDIG later described as a stack of failure surfaces. By the time rsETH was accepted as collateral in a dozen places, its safety rested on a chain of assumptions almost nobody had actually inspected: that Kelp’s restaking was sound, that its bridge was honest, and, buried at the very bottom, that a single off-chain verifier would never be fooled. It was fooled, and every layer built on top inherited the lie. A token designed to make ETH more useful had also made a single point of failure far more contagious.

Why $292 Million Became a Systemwide Problem

A stolen $292 million is a catastrophe for the protocol that loses it. What made KelpDAO different is that the damage refused to stay inside Kelp.

rsETH was not sitting quietly in wallets. It had been deposited as collateral across the biggest money markets in DeFi, above all Aave, along with Compound and various layer 2 deployments. When 116,500 rsETH suddenly had nothing behind it, those tokens did not stop existing; holders could still, in principle, borrow against them. The unbacked collateral threatened to leave lenders holding loans that could never be repaid, and by one KuCoin tally bridge exploits accounted for about $329 million across eight incidents in 2026, part of more than $750 million in total crypto hacks, with KelpDAO the dominant chunk.

Research firm NYDIG, in a note titled The Butterfly Effect Comes to DeFi, estimated the resulting bad debt at somewhere between $123 million and $230 million, concentrated on layer 2 networks, and flagged Mantle as especially exposed, with about 71 percent of its wrapped-ETH pool at risk. NYDIG’s broader point was structural: every layer in a DeFi strategy adds another surface that can fail, and no participant in the stack, Aave included, had full visibility into the risks baked into the layers above or below it. Aave accepted rsETH as collateral; it never assessed that rsETH’s bridge ran on a single verifier.

Then came the run. NYDIG documented borrowers with no rsETH exposure at all getting hurt: institutions borrowing stablecoins against Bitcoin or Ether watched their rates jump from about 3.5 percent to 14 percent within 48 hours, a near-quadrupling driven entirely by panic withdrawals from unrelated pools. The logic was rational and therefore dangerous. Depositors pulled funds not because their own positions touched the bad debt, but because the sensible move, when losses on a shared platform cannot be quantified, is to leave before those losses get socialized.

Sergej Kunz, co-founder of 1inch, had warned about exactly this. Once bridged assets are treated as legitimate collateral everywhere else, he told CoinDesk, a single failure stops being local: “That’s how contagion happens.” He also offered a blunt diagnosis of why bridges keep breaking in the first place: “Security is often not the top priority. Teams focus on launching quickly.”

The Old Playbook: Backstop, Bounty, or Bust

Before April 2026, a bridge that lost nine figures had three plausible endings, and one of them was no ending at all.

The first is the deep-pocket backstop, where a single well-funded entity simply eats the loss. When the Wormhole bridge lost about $325 million in February 2022, Jump Crypto replaced all 120,000 ETH within roughly a day, per Halborn, and users never felt it. When Ronin lost around $625 million the following month, still the largest bridge theft on record, Sky Mavis raised a $150 million round led by Binance and covered the rest from its own balance sheet to reimburse players, as CoinDesk reported at the time.

The second is the white-hat return, a negotiation with the attacker. Poly Network’s 2021 loss of more than $610 million ended with the team politely addressing “Mr. White Hat,” offering a bounty, and getting essentially everything back. Nomad’s $190 million free-for-all in 2022 clawed back only about $36 million under a 10 percent bounty. The Liquid Network’s roughly $320 million peg-out this September ended with self-described white hats returning about 3,400 of nearly 4,000 BTC and keeping the rest, per news.bitcoin.com.

The third ending is nothing. Harmony’s Horizon bridge lost about $100 million in 2022 and recovered a sliver. Multichain simply collapsed in 2023 after its operator was detained in China and the team lost access to keys he alone controlled; users are still waiting. For scale, Chainalysis counted roughly $2 billion stolen across 13 bridge hacks in 2022 alone, about 69 percent of that year’s crypto theft. Ranked by how they ended, the landmark cases look like this.

BridgeDateAmountHow it ended
Poly NetworkAug 2021~$610MAttacker returned nearly all after public negotiation
WormholeFeb 2022~$325MJump Crypto replaced 120,000 ETH in about a day
RoninMar 2022~$625MSky Mavis backstop ($150M raise plus balance sheet)
Harmony HorizonJun 2022~$100MMinimal recovery; users largely uncompensated
NomadAug 2022~$190MAbout $36M returned under a 10 percent bounty
BNB BridgeOct 2022~$566M mintedChain halt froze most; roughly $100M left the chain
MultichainJul 2023~$130M+Operator collapse; still unresolved
KelpDAOApr 2026~$292MCoalition rebuild; backing fully restored
Liquid NetworkSep 2026~$320MWhite hats returned ~3,400 of ~4,000 BTC

The 2022 figures track the reporting at the time, including Halborn’s post-mortem of the BNB Chain forged-proof hack, where a fast chain halt froze most of the roughly $566 million an attacker had minted.

A Different Answer: The Coalition Rebuild

KelpDAO had none of the first three exits cleanly available. There was no Jump Crypto standing behind rsETH, no single treasury large enough to write a $292 million check, and the attacker was a North Korean state group with no interest in a bounty. Left alone, rsETH would have collapsed, and the bad debt would have rippled through Aave and beyond.

So something else happened. Within days, a coalition calling itself DeFi United formed around Aave, the money market with the most to lose, and set out to rebuild rsETH’s backing directly. The pitch was not charity. It was self-interest correctly understood: rsETH had become load-bearing infrastructure, and its failure would have damaged protocols that had nothing to do with Kelp’s bridge configuration. Better to fill the hole together than let it swallow the neighborhood.

Consensys founder Joseph Lubin, who committed up to 30,000 ETH through Consensys, framed it as an ecosystem reflex. “The Ethereum ecosystem has always been at its best when it moves together,” he said, per The Block, describing DeFi United as a broad, coordinated response meant to protect users and strengthen shared infrastructure. By 27 April, pledges had passed $303 million, more than 100,000 ETH, according to CoinDesk. That is the novel part. This was not one backer and not the thief; it was the industry recapitalizing one of its own.

Who Paid, and How Much

The roster read like a who’s-who of Ethereum DeFi, including protocols that compete head-on for the same deposits.

ContributorCommitmentForm
Consensys / Joseph LubinUp to 30,000 ETHContribution
Mantle30,000 ETHCredit facility (loan)
Aave DAO25,000 ETHGovernance-approved deployment
Stani Kulechov (Aave founder)5,000 ETHPersonal donation
EtherFi5,000 ETHProposed contribution
CompoundUp to 3,000 ETHContribution
LidoUp to 2,500 stETHContribution
Renzo$10M+Treasury deposits
Babylon Foundation$3M USDTContribution
Ethena, Frax, Ink, Tyro, LayerZero, BGD Labs, othersUndisclosed / smallerVarious

The competitive dynamics are worth dwelling on. Aave and Compound are rival lending markets; Lido, EtherFi, and Renzo all chase the same staking and restaking deposits that rsETH itself competes for. They funded the rescue anyway, because a public rsETH failure would have tainted the whole liquid-restaking category and the money markets that hold it. Note too that most pledges were structured as loans or staged commitments rather than gifts: Mantle’s 30,000 ETH, for instance, was a credit facility, not a handout, per the coalition’s published plan.

The scale came together fast. By 24 April, less than a week after the hack, a public tracker showed the coalition had already gathered roughly 69,500 ETH toward its 100,000 ETH goal, about $161 million at the time, arriving from hundreds of separate wallets, per Phemex. Watching a nine-figure rescue assemble transaction by transaction, in public, was itself a first for an industry more accustomed to watching money leave that way.

The Technical Cleanup

Pledges are not the same as a fix. The harder problem was mechanical: how do you turn scattered promises of ETH into rsETH that is once again worth exactly one ETH, without letting the attacker or opportunists skim the recapitalization on the way in?

The plan, which FinanceFeeds described as reading like a coordinated cleanup operation, deployed the committed ETH in stages into Kelp’s rsETH bridge adapter, deliberately validating the newly hardened bridge security before releasing the full pledges. In parallel, the coalition ran a governance-approved liquidation sequence targeting eight affected Aave V3 positions plus residual holdings on Compound, unwinding bad loans in a controlled way and, per CoinDesk, recovering on the order of 13,000 ETH of collateral rather than dumping it into a panicked market.

The arithmetic mattered. NYDIG put the net shortfall to recapitalize at about 112,204 rsETH, and after the 30,766 ETH the Arbitrum Security Council had frozen and the collateral recovered from lending positions, the coalition’s fundraising target settled near 100,000 ETH. That was the amount its members judged necessary to give every rsETH holder a clean one-to-one claim on underlying ETH again.

Five Weeks to Whole

The rebuild took about five weeks from theft to full restoration.

  • 18 April: the attack drains about 116,500 rsETH; Kelp pauses contracts, blocking a further $95 million, and the Arbitrum Security Council freezes 30,766 ETH.
  • Late April: DeFi United forms, and commitments climb past $303 million and 100,000 ETH.
  • 13 May: the first 25,000 rsETH batch is deposited, and cross-chain bridging and claims reopen.
  • Mid-to-late May: a final batch of 20,373.72 rsETH goes into the LayerZero OFT adapter.
  • Completion: rsETH backing is restored to about 100.01 percent, roughly five weeks after the hack, with no losses passed on to holders.

By the time the last batch landed, per CoinCentral and Crypto Briefing, rsETH held a backing ratio of about 100.01 percent, a hair over fully collateralized. Holders who had done nothing wrong, and who for a few weeks in April held a token that was quietly insolvent, ended up whole.

The Blame Game: Kelp Versus LayerZero

One thing the rescue did not settle was fault.

LayerZero and Kelp spent the weeks after the hack pointing at each other. LayerZero’s position was that Kelp had manually downgraded the rsETH deployment to a 1-of-1 DVN, and that a single-verifier configuration fell outside its bug-bounty scope. Kelp countered that the setup was effectively sanctioned by LayerZero at deployment time, per CoinDesk. The dispute matters because it is the crux of every attestation-based bridge: someone chooses how many independent verifiers must agree, and that choice, not the code, is often the whole security model.

LayerZero raised its DVN minimums afterward, ending the practice of shipping production deployments behind a single verifier. But the recovery went ahead without waiting for anyone to admit liability, which is precisely what made it unusual. The coalition treated the loss as a shared problem to be solved first and adjudicated later.

Four Billion Dollars Voted With Its Feet

Markets did not wait for the postmortem either.

Within weeks of the hack, roughly $4 billion in bridged assets, including Kraken’s kBTC and tokens from Lombard, migrated away from LayerZero toward Chainlink’s CCIP, according to CoinDesk. Johann Eid, a Chainlink executive, called it a “continued flight to safety.” CCIP secures each lane with a network of 16 or more independent node operators plus a separate risk-management layer, a deliberately higher bar than a single configurable DVN. The migration kept growing later in the year as larger custodians moved wrapped assets across.

The lesson the market drew was not that bridges are doomed; it was that the number of independent parties who must agree before your money moves is the security budget, and that a budget of one is no budget at all.

Is Too Connected to Fail a Feature or a Bug?

The KelpDAO rescue is easy to celebrate. It is also worth being suspicious of.

In banking, too big to fail is a criticism, not a compliment. It describes institutions that can take reckless risks because they expect someone to catch them. DeFi has just discovered its own version, too connected to fail: if a token becomes systemically embedded enough, a bailout coalition may assemble to save it, which is wonderful for holders and quietly corrosive for incentives. Why insist on a multi-verifier bridge, or pay for a second audit, if being important enough means the neighbors will rebuild your backing?

The coalition rebuild is not a safety net anyone should count on, because it worked only under a specific set of conditions. rsETH was systemically important; the loss was a backing hole that fresh ETH could refill rather than vaporized underlying assets; and the whole thing sat inside one broadly aligned ecosystem where Aave, Lido, Mantle, and Consensys all had a shared stake in Ethereum DeFi’s reputation. Strip out any one of those, and the model evaporates.

Compare Harmony or Multichain. Both lost comparable or larger sums; neither was load-bearing enough, or embedded in a cohesive enough ecosystem, for a rescue to coalesce. Their users got the third ending: nothing. Too connected to fail is not a promise the industry can make to everyone. It is a privilege that accrues to whatever the ecosystem decides it cannot afford to lose.

Vitalik Buterin’s 2022 warning still frames the underlying problem. He argued there are “fundamental limits to the security of bridges that hop across multiple zones of sovereignty,” per Cointelegraph; a multi-chain world, in his view, yes, a cross-chain one, no. The DeFi United rescue does not refute him. It shows what it costs to clean up when the limit gets hit anyway.

Recovery modelHow the hole gets filledWho bears the lossExamplesRepeatable?
Deep-pocket backstopOne well-funded backer covers itThe backerWormhole (Jump), Ronin (Sky Mavis)Only if a backer exists
White-hat returnAttacker returns funds for a bountyAttacker forfeits mostPoly Network, Nomad, LiquidOnly if the attacker cooperates
Coalition rebuildMany protocols pool capitalContributors (often as loans)KelpDAO / DeFi UnitedOnly for systemic assets
NothingThe hole is never filledUsersHarmony, MultichainAlways available, worst outcome

A Bailout by Any Other Name

DeFi likes to think of itself as the opposite of the banking system it was built to route around. The KelpDAO rescue complicates that story, because it rhymes with one of traditional finance’s most famous save operations.

In 1998, when the hedge fund Long-Term Capital Management imploded and threatened to drag its lenders down with it, the Federal Reserve Bank of New York did not write a check. It gathered the fund’s major creditors and organized a private consortium of large banks that put up billions of dollars to wind the positions down in an orderly way, precisely because LTCM was too entangled with everyone else to be allowed to fail messily. A decade later, the 2008 rescues turned “too big to fail” into a permanent part of the language.

DeFi United is that pattern rebuilt without the central bank. No regulator convened it, no public money touched it, and the whole thing settled on-chain in weeks rather than dragging through years of litigation. That is genuinely new, and in some ways healthier: the people who had profited from rsETH’s ubiquity were the ones who paid to save it, not taxpayers. But the underlying logic is identical, and so is the hazard. Once market participants learn that sufficiently interconnected positions get rescued, the incentive to avoid becoming dangerously interconnected gets weaker. Crypto spent a decade mocking bailouts. It just ran one, on its own terms, and mostly congratulated itself.

What It Means for US Users and the SEC

For a reader in the United States, the most important sentence in this whole story is the one nobody says out loud: no regulator was going to make you whole.

There is no federal insurance for a cross-chain bridge and no mechanism for the Securities and Exchange Commission to order refunds after a DeFi exploit. The agency can sue issuers and intermediaries; it cannot reverse an on-chain transfer. That regulatory vacuum only widened as the legislative timeline slipped, a story we tracked when Washington’s crypto rulebook deadlines reset after the CLARITY Act stalled. If your bridged asset evaporates, your recourse is whatever the market improvises: a backstop, a bounty, a coalition, or nothing.

Enforcement against the attackers runs into its own walls. The KelpDAO funds were stolen by a North Korean group and routed through the usual laundering rails, the same infrastructure that has made compliance a running battle for exchanges; OKX’s $504 million settlement over weak KYC and AML controls is a reminder of how much pressure sits on the on-ramps and off-ramps. But sanctioning the tools has proven legally fragile: after courts found the Treasury had overstepped, Tornado Cash was delisted from the sanctions list in March 2025, per Forbes. The same property that makes an immutable bridge hard to secure, that no one controls it once deployed, makes it hard to sanction after the fact.

What has held up better is enforcement against people. North Korea’s crews cash out through a shrinking set of intermediaries, and investigators lean on that chokepoint: victims and agencies now race to freeze funds at exchanges before they scatter, exactly as the Arbitrum Security Council did within hours of the KelpDAO theft. The uncomfortable truth for a US investor is that this machinery is built to punish attackers and pressure intermediaries, not to return your money. Recovery, when it comes at all, still depends on private actors deciding it is in their own interest, which is precisely what makes the DeFi United model worth studying rather than dismissing.

There is even a tax wrinkle. KelpDAO holders were made whole, so most have no loss to claim. Holders of bridges that ended with nothing face a harder question, because personal theft-loss deductions are sharply limited under current US rules, a corner of the code we walked through in our guide to crypto taxes and the bill the House just advanced. Being rescued, it turns out, is also the cleanest outcome on your return.

How to Tell If Your Bridged Asset Is Too Connected, or Too Alone

You cannot audit LayerZero’s RPC nodes yourself. But you can read the two things that decided the KelpDAO outcome, before you bridge.

First, the verifier set. Ask how many independent parties must agree before your tokens move, and treat 1-of-1 as a red flag in flashing letters. A single DVN, a single relayer, or a small federation is one point of failure no matter how reputable the operator; the KelpDAO adapter, the Liquid federation, and the Ronin validator set all cleared their nominal thresholds and lost the money anyway. More independent verifiers, or a native mint-and-burn design that removes the wrapped honeypot entirely, is the direction the whole industry moved after this hack.

Second, and more honestly: how connected is your asset? A coalition materialized for rsETH because rsETH mattered to a dozen protocols at once. If you are holding a niche wrapped token on a small chain, no DeFi United is coming for you; you are relying entirely on the operator’s own backstop or the kindness of the thief. Systemic embedding cuts both ways: it is what spreads the contagion, and it is also the only reason anyone rebuilds. For everyone outside that charmed circle, the safest bridge remains the one you do not have to trust, or the trip you do not take at all.

There is a third habit worth forming, and it is the cheapest of the three: prefer assets issued natively on each chain over wrapped copies parked in a vault. Circle’s stablecoin transfer protocol, for instance, burns real USDC on one chain and mints it on another, so there is no pooled honeypot to drain and no IOU that can go unbacked. A growing share of serious cross-chain volume now moves this way, or through intent-based systems that never mint a bridge token at all. The KelpDAO rescue proved the industry can clean up after a wrapped-asset failure. Not creating the wrapper in the first place is a better plan than counting on the cleanup.

Frequently Asked Questions

How much was stolen in the KelpDAO bridge hack?

About 116,500 rsETH, worth roughly $292 million on 18 April 2026, which made it the largest DeFi hack of the year. A follow-up attempt to mint a further 40,000 rsETH, around $95 million, was blocked when Kelp paused its contracts.

What was DeFi United?

DeFi United was a coalition that formed around Aave after the hack, drawing pledges from more than a dozen protocols, DAOs, and founders, including Consensys, Mantle, EtherFi, Compound, and Lido. Together they committed more than $303 million, over 100,000 ETH, to rebuild rsETH’s backing.

Did KelpDAO users lose money?

No. The coalition restored rsETH’s backing to about 100 percent over roughly five weeks, cross-chain bridging reopened on 13 May 2026, and no losses were passed on to rsETH holders.

Was the KelpDAO hack a smart-contract bug?

No. The audited contracts behaved as written. Attackers compromised LayerZero’s off-chain verification infrastructure, poisoning internal RPC nodes and knocking out an external one, to fool a single-verifier bridge into releasing unbacked tokens. LayerZero attributed the attack to North Korea’s Lazarus Group.

Can the SEC recover funds after a bridge hack?

No. There is no US mechanism for the SEC to reverse an on-chain transfer or refund victims of a DeFi exploit. Recovery depends on a backstop, a white-hat return, or a coalition rebuild; regulators can pursue the attackers, but sanctioning immutable code has proven legally fragile.

By Anneke de Vries, security-exploits correspondent at HOGE Wire.

Share 𝕏 Post Telegram