Massive $292 Million Heist: Kelp DAO Falls Victim to Exploitation
Recent Developments in the Crypto Space KELP DAO BREACH: A significant cross-chain bridge, holding nearly one-fifth of the circulating supply of a restaked ether token, has been drained. The aftermath is spreading rapidly through DeFi, outpacing Kelp DAO's efforts to pause contracts. Over the weekend, at 17:35 UTC, an attacker drained 116,500 rsETH (restaked ether) from Kelp DAO's LayerZero-powered bridge, valued at approximately $292 million at current prices. This amounts to roughly 18% of rsETH's 630,000 token circulating supply, as tracked by CoinGecko. LayerZero serves as a cross-chain messaging layer, facilitating verified communication between different blockchains. Kelp DAO operates as a liquid restaking protocol, directing user-deposited ETH through EigenLayer to generate additional yield beyond standard Ethereum staking rewards and issuing rsETH as a tradable receipt. The breached bridge held the rsETH reserve backing wrapped versions of the token deployed across over 20 other blockchains. The attacker deceived LayerZero's cross-chain messaging layer into accepting a fake instruction from another network, prompting Kelp's bridge to release 116,500 rsETH to an attacker-controlled address. Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, at 18:21 UTC. Two subsequent attempts at 18:26 UTC and 18:28 UTC were reverted, each carrying the same LayerZero packet in an attempt to drain an additional 40,000 rsETH, valued at approximately $100 million. NORTH KOREA'S CRYPTO ATTACK PLAYBOOK: Less than three weeks after North Korea-linked hackers used social engineering to target crypto trading firm Drift, hackers linked to the nation appear to have executed another significant exploit, this time targeting Kelp. The attack on Kelp, a restaking protocol integrated into LayerZero’s cross-chain infrastructure, suggests an evolution in the tactics employed by North Korea-linked hackers. Rather than solely seeking bugs or stolen credentials, they are now exploiting fundamental assumptions built into decentralized systems. The two incidents collectively point to a more organized effort, as North Korea continues to escalate its attempts to hijack funds from the crypto sector. "This is not a series of isolated incidents; it represents a pattern," said Alexander Urbelis, chief information security officer and general counsel at ENS Labs. "You cannot resolve this issue through patching alone; it requires addressing the procurement schedule." More than $500 million was siphoned off in the Drift and Kelp exploits within a span of two weeks. At its core, the Kelp exploit did not involve breaking encryption or cracking keys; the system functioned as designed. However, attackers manipulated the data feeding into the system, forcing it to rely on compromised inputs and thereby approving transactions that never actually occurred. AFFECT ON AAVE: An attacker exploited this setup by forging a transfer message that appeared valid. The system approved the transfer despite the tokens never being removed from the sending chain, effectively creating new tokens without backing. This resulted in the release of 116,500 rsETH from the Ethereum-side bridge. Instead of selling the assets on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed roughly $190 million in ETH and related assets across Ethereum and Arbitrum, according to the report. This exposed Aave to collateral whose backing may be significantly impaired. Aave Labs responded quickly to contain the risk, freezing rsETH markets across its deployments, setting loan-to-value ratios to zero, and halting new borrowing against the asset within hours. The outcome now largely depends on how Kelp handles the shortfall. If losses are spread across all rsETH holders, the token would face an estimated 15% depegging, resulting in about $124 million in bad debt for Aave. If losses are instead isolated to Layer 2 networks, the impact would be more severe, with bad debt rising to roughly $230 million and concentrated on networks such as Arbitrum and Mantle. COINBASE REPORT ON QUANTUM COMPUTING RISKS: A new report commissioned by Coinbase sounds a cautious yet urgent alarm regarding the risks posed by quantum computing to the crypto industry. The 50-page paper, authored by an independent advisory board including prominent cryptographers and academics, concludes that while current blockchains remain secure, the emergence of a "fault-tolerant quantum computer" capable of breaking widely used encryption is increasingly plausible, and preparation must begin immediately. Recent months have seen growing concerns around quantum risk, with Google researchers estimating that a sufficiently advanced quantum computer could potentially break Bitcoin’s cryptography. Major crypto ecosystems have already started outlining their responses, with the Ethereum Foundation proposing new types of digital signatures designed to be safe against quantum computers, and Solana experimenting with quantum-resistant wallet designs. The report emphasizes that current quantum machines are far from powerful enough to crack the cryptography underpinning Bitcoin, Ethereum, and other networks, requiring vast computational overhead that remains a significant engineering challenge.