Exploitation of Kelp DAO Results in $292 Million Loss

Recent News KELP DAO BREACH: A significant cross-chain bridge, holding nearly one-fifth of the total supply of restaked ether tokens, has been drained. The aftermath of this event is spreading rapidly throughout the DeFi sector, outpacing Kelp DAO's ability to pause contracts. Over the weekend, at 17:35 UTC, an attacker drained 116,500 rsETH, worth approximately $292 million at current prices, from Kelp DAO's LayerZero-powered bridge. This represents about 18% of the 630,000 rsETH tokens in circulation, according to CoinGecko. LayerZero serves as the infrastructure enabling different blockchains to send verified instructions to each other. Kelp DAO is a liquid restaking protocol that takes user-deposited ETH, routes it through EigenLayer to earn additional yield beyond standard Ethereum staking rewards, and issues rsETH as a tradable receipt. The drained bridge held the rsETH reserve backing wrapped versions of the token deployed on over 20 other blockchains. The attacker deceived LayerZero's cross-chain messaging layer into believing a valid instruction had arrived from another network, prompting Kelp's bridge to release 116,500 rsETH to an attacker-controlled address. Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, at 18:21 UTC. Two subsequent attempts at 18:26 UTC and 18:28 UTC were reverted, each carrying the same LayerZero packet in an attempt to drain another 40,000 rsETH, worth roughly $100 million. NORTH KOREA'S CRYPTO EXPLOITATION PLAYBOOK: Less than three weeks after North Korea-linked hackers used social engineering to target crypto trading firm Drift, hackers tied to the nation appear to have executed another major exploit with Kelp. The attack on Kelp, a restaking protocol integrated into LayerZero's cross-chain infrastructure, suggests an evolution in North Korea-linked hackers' tactics, shifting from seeking bugs or stolen credentials to exploiting the fundamental assumptions built into decentralized systems. The combined incidents indicate a more organized approach, as North Korea escalates its efforts to hijack funds from the crypto sector. "This is not a series of incidents; it is a cadence," said Alexander Urbelis, chief information security officer and general counsel at ENS Labs. "You cannot patch your way out of a procurement schedule." More than $500 million was siphoned across the Drift and Kelp exploits in just over two weeks. At its core, the Kelp exploit did not involve breaking encryption or cracking keys. The system functioned as designed, but attackers manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never occurred. AAVE IMPACTED BY KELP DAO BREACH: An attacker exploited this setup by forging a transfer message that appeared valid. The system approved the transfer, even though the tokens were never removed from the sending chain, effectively creating new tokens without backing. This resulted in the release of 116,500 rsETH from the Ethereum-side bridge. Instead of selling the assets on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed roughly $190 million in ETH and related assets across Ethereum and Arbitrum. This exposed Aave to collateral whose backing may be significantly impaired. Aave Labs moved quickly to contain the risk, freezing rsETH markets across its deployments, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on how Kelp handles the shortfall. If losses are spread across all rsETH holders, the token would face an estimated 15% depegging, resulting in about $124 million in bad debt for Aave. If losses are instead isolated to Layer 2 networks, the impact would be more severe, with bad debt rising to roughly $230 million and concentrated on networks such as Arbitrum and Mantle. COINBASE REPORT ON QUANTUM COMPUTING RISKS: A new report commissioned by Coinbase sounds a cautious yet urgent alarm: Quantum computing won't compromise crypto tomorrow, but the industry cannot afford to wait. The 50-page paper, authored by an independent advisory board including prominent cryptographers and academics, concludes that while current blockchains remain secure, a future "fault-tolerant quantum computer" capable of breaking widely used encryption is increasingly plausible, and preparation must begin now. Recent months have seen concerns around quantum risk move further into the mainstream. Google researchers have published estimates suggesting that a sufficiently advanced quantum computer could one day break Bitcoin's cryptography. Major crypto ecosystems have started mapping out their responses, with the Ethereum Foundation proposing new digital signatures designed to be safe against quantum computers, and Solana experimenting with quantum-resistant wallet designs. The report stresses that current quantum machines are far from powerful enough to crack the cryptography underpinning Bitcoin, Ethereum, and other networks, but breaking standard encryption would require vast computational overhead, a milestone still considered a major engineering challenge.