Exploitation of Kelp DAO: $292 Million Lost in Latest Crypto Heist
Recent News KELP DAO BREACH: A significant cross-chain bridge holding nearly one-fifth of the circulating supply of a restaked ether token has been drained, and the consequences are spreading rapidly through DeFi, outpacing Kelp DAO's efforts to pause contracts. Over the weekend, at 17:35 UTC, an attacker extracted 116,500 rsETH (restaked ether) from Kelp DAO's LayerZero-powered bridge, valued at approximately $292 million at current prices, representing about 18% of rsETH's 630,000 token circulating supply as tracked by CoinGecko. LayerZero serves as a cross-chain messaging layer, enabling different blockchains to send verified instructions to each other. Kelp DAO operates as a liquid restaking protocol, utilizing user-deposited ETH, routing it through EigenLayer to generate additional yield beyond standard Ethereum staking rewards, and issuing rsETH as a tradeable receipt. The breached bridge held the rsETH reserve backing wrapped versions of the token deployed across more than 20 other blockchains. The attacker deceived LayerZero's cross-chain messaging layer into believing a legitimate instruction had arrived from another network, prompting Kelp's bridge to release 116,500 rsETH to an attacker-controlled address. Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, at 18:21 UTC. Two follow-up attempts at 18:26 UTC and 18:28 UTC both reverted, each carrying the same LayerZero packet in an attempt to drain another 40,000 rsETH, worth roughly $100 million. NORTH KOREA'S CRYPTO EXPLOITATION PLAYBOOK: Less than three weeks after North Korea-linked hackers used social engineering to target crypto trading firm Drift, hackers tied to the nation appear to have executed another major exploit, this time on Kelp. The attack on Kelp, a restaking protocol integrated into LayerZero's cross-chain infrastructure, suggests an evolution in the tactics of North Korea-linked hackers, who are no longer just seeking bugs or stolen credentials but are exploiting the fundamental assumptions underlying decentralized systems. The combined incidents point to a more organized effort than isolated hacks, as North Korea continues to escalate its attempts to hijack crypto sector funds. "This is not a series of incidents; it is a cadence," stated Alexander Urbelis, chief information security officer and general counsel at ENS Labs. "You cannot patch your way out of a procurement schedule." More than $500 million was siphoned across the Drift and Kelp exploits in just over two weeks. At its core, the Kelp exploit did not involve breaking encryption or cracking keys; the system functioned as designed. Instead, attackers manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never occurred. Aave Exposed to Kelp DAO Hack: An attacker exploited this setup by forging a transfer message that appeared valid. The system approved the transfer despite the tokens never being removed from the sending chain, effectively creating new tokens without backing and releasing 116,500 rsETH from the Ethereum-side bridge. Rather than selling the assets on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed roughly $190 million in ETH and related assets across Ethereum and Arbitrum. This exposed Aave to collateral whose backing may be significantly impaired. Aave Labs moved quickly to contain the risk, freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset within hours. The outcome now largely depends on how Kelp handles the shortfall. If losses are spread across all rsETH holders, the token would face an estimated 15% depegging, resulting in about $124 million in bad debt for Aave. If losses are isolated to Layer 2 networks, the impact would be more severe, with bad debt rising to roughly $230 million and concentrated on networks like Arbitrum and Mantle. Coinbase Report on Quantum Computing Risks: A report commissioned by Coinbase sounds a cautious yet urgent alarm: Quantum computing won't compromise crypto immediately, but the industry cannot afford to wait. The 50-page paper concludes that while current blockchains remain secure, the possibility of a future "fault-tolerant quantum computer" capable of breaking widely used encryption is increasingly plausible, and preparation must begin now. Recent months have seen concerns around quantum risk move into the mainstream, with Google researchers estimating that a sufficiently advanced quantum computer could break Bitcoin's cryptography. Major crypto ecosystems have started mapping out their responses, with the Ethereum Foundation proposing new digital signatures safe against quantum computers and Solana experimenting with quantum-resistant wallet designs. The report stresses that current quantum machines are far from powerful enough to crack the cryptography underpinning Bitcoin, Ethereum, and other networks, but emphasizes the need for proactive measures to ensure future security.