Crypto Exploit of 2026: $292 Million Stolen from Kelp DAO, Leaving 20 Chains Vulnerable

A significant attack has been carried out on a cross-chain bridge, resulting in the loss of nearly 18% of the circulating supply of a restaked ether token. The breach occurred on Saturday at 17:35 UTC, with an attacker exploiting the bridge to drain 116,500 rsETH, equivalent to roughly $292 million. This incident has triggered a series of emergency measures across various DeFi platforms, including Aave, SparkLend, and Fluid, which have frozen their rsETH markets. The attack has also led to a decline in the value of AAVE, with the token falling by approximately 10% as the market responds to the potential bad debt. The affected bridge, which is part of the Kelp DAO protocol, held the reserve backing wrapped versions of the token deployed on over 20 other blockchains. The attacker manipulated LayerZero's cross-chain messaging layer, tricking it into releasing the rsETH to an attacker-controlled address. In response, Kelp's emergency pauser multisig froze the protocol's core contracts, preventing further attacks. However, the incident has raised concerns about the potential for panic redemptions on layer 2 blockchains, which could pressure the unaffected Ethereum supply and force Kelp to unwind its restaking positions. The fallout from the attack is ongoing, with several platforms, including Lido Finance and Ethena, taking precautionary measures to mitigate potential risks. The incident is the largest DeFi exploit of 2026, surpassing the recent attack on Solana-based perpetuals protocol Drift, which resulted in the loss of approximately $285 million.