Loading article…
Kelp DAO lost $293 million (18% of rsETH supply) in a April 19 exploit. Learn how the breach works, DAO basics, and what to watch next.
A hacker siphoned roughly $293 million—about 18% of the rsETH token supply— from Kelp DAO on April 19, underscoring the security challenges facing decentralized autonomous organizations (DAOs) today [2].
| At a glance | |
|---|---|
| Amount stolen | $293 million |
| % of rsETH supply | 18 % (≈116,500 rsETH) |
| Date of exploit | April 19, 2026 |
| Catalyst | LayerZero cross‑chain message spoofing |
A DAO (decentralized autonomous organization) is an online group that governs itself through smart contracts rather than a central hierarchy. Its primary purpose is often to manage a treasury of crypto assets, with voting power typically tied to a governance token that members stake [1]. Because the code is publicly visible on the blockchain and immutable, DAOs promise transparent, trust‑less coordination—but they also inherit the same code‑level vulnerabilities that can be exploited by attackers.
Kelp DAO operates a liquid restaking protocol, letting users deposit staked assets such as stETH or cbETH and receive a receipt token called rsETH. To enable rsETH on more than 20 chains, Kelp maintains a bridge that holds a large reserve of the token. At 17:35 UTC on April 19, an attacker funded a wallet through the privacy tool Tornado Cash and then spoofed a message to LayerZero’s EndpointV2 contract, making the bridge believe a legitimate cross‑chain instruction had arrived. The fake message triggered the release of 116,500 rsETH—about 18 % of the total circulating supply of roughly 630,000 tokens—directly to the attacker’s address [2].
Kelp’s emergency team paused the rsETH contracts across mainnet and several L2s within an hour, freezing deposits and withdrawals to limit further damage. The incident illustrates how a single vulnerability in a cross‑chain bridge can jeopardize a large portion of a DAO’s treasury and ripple through the broader DeFi ecosystem, where rsETH is commonly used as collateral.
The Kelp incident shows that while DAOs enable novel, token‑driven governance, their reliance on immutable smart‑contract code creates a single point of failure. As more capital flows into DAO‑managed treasuries, the industry’s ability to secure cross‑chain bridges will determine whether the promise of decentralized finance can survive such high‑profile attacks.
Coverage is mostly measured — 127 of 131 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Jul 3, 2026 · How we report
A DAO, or decentralized autonomous organization, is an entity with no central governing body that uses a bottom-up management approach to make decisions.
MakerDAO uses smart contracts to facilitate an overcollateralized loan process, adjusting collateral types and interest rates to keep the stablecoin's value near one US dollar.
MKR is a governance token that allows its owners to vote on proposed changes to the system's smart contracts and parameters.
In August 2024, MakerDAO underwent a rebranding to become known as Sky.