Major Exploit: Kelp DAO Loses $292 Million

Recent News KELP DAO BREACH: A significant cross-chain bridge holding nearly one-fifth of the circulating supply of a restaked ether token has been drained, and the repercussions are spreading rapidly through DeFi, outpacing Kelp DAO's contract pause. At 17:35 UTC over the weekend, an attacker drained 116,500 rsETH from Kelp DAO's LayerZero-powered bridge, valued at approximately $292 million at current prices, accounting for about 18% of rsETH's 630,000 token circulating supply tracked by CoinGecko. LayerZero serves as a cross-chain messaging layer, enabling different blockchains to send verified instructions to each other. Kelp DAO is a liquid restaking protocol that takes user-deposited ETH, routes it through EigenLayer to earn additional yield beyond standard Ethereum staking rewards, and issues rsETH as a tradeable receipt. The breached bridge held the rsETH reserve backing wrapped versions of the token deployed on over 20 other blockchains. The attacker deceived LayerZero's cross-chain messaging layer into believing a valid instruction had been received from another network, triggering Kelp's bridge to release 116,500 rsETH to an attacker-controlled address. Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, at 18:21 UTC. Two subsequent attempts at 18:26 UTC and 18:28 UTC both failed, each carrying the same LayerZero packet attempting another 40,000 rsETH drain worth roughly $100 million. NORTH KOREA'S CRYPTO ATTACK PLAYBOOK: Less than three weeks after North Korea-linked hackers used social engineering to target crypto trading firm Drift, hackers tied to the nation appear to have executed another significant exploit with Kelp. The attack on Kelp, a restaking protocol integrated into LayerZero's cross-chain infrastructure, suggests an evolution in North Korea-linked hackers' operations, as they now exploit the fundamental assumptions built into decentralized systems, rather than merely seeking bugs or stolen credentials. The two incidents collectively point to a more organized effort by North Korea to hijack funds from the crypto sector. "This is not a series of incidents; it is a cadence," said Alexander Urbelis, chief information security officer and general counsel at ENS Labs. "You cannot patch your way out of a procurement schedule." More than $500 million was siphoned across the Drift and Kelp exploits in just over two weeks. The Kelp exploit did not involve breaking encryption or cracking keys; instead, attackers manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never occurred. AAVE IMPACTED BY KELP DAO HACK: An attacker exploited this setup by forging a transfer message that appeared valid, causing the system to approve the transfer even though the tokens were never removed from the sending chain, effectively creating new tokens without backing. This resulted in the release of 116,500 rsETH from the Ethereum-side bridge. Rather than selling the assets on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed roughly $190 million in ETH and related assets across Ethereum and Arbitrum. Aave Labs moved quickly to contain the risk, freezing rsETH markets across its deployments, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on how Kelp handles the shortfall. If losses are spread across all rsETH holders, the token would face an estimated 15% depegging, resulting in about $124 million in bad debt for Aave. If losses are instead isolated to Layer 2 networks, the impact would be far more severe, with bad debt rising to roughly $230 million and concentrated on networks such as Arbitrum and Mantle. COINBASE REPORT HIGHLIGHTS QUANTUM COMPUTING RISKS: A new report commissioned by Coinbase sounds a cautious yet urgent alarm: Quantum computing won't break crypto tomorrow, but the industry cannot afford to wait. The report concludes that while current blockchains remain secure, a future "fault-tolerant quantum computer" capable of breaking widely used encryption is increasingly plausible, and preparation must begin now. Recent months have seen concerns around quantum risk move further into the mainstream, with Google researchers publishing estimates suggesting that a sufficiently advanced quantum computer could one day break Bitcoin's cryptography. Major crypto ecosystems have already started mapping out their responses, with the Ethereum Foundation proposing new types of digital signatures designed to be safe against quantum computers, and Solana experimenting with quantum-resistant wallet designs.