Loading article…
Kelp DAO completes its rsETH recovery plan, transferring the final batch of tokens and resuming full functionality after a $293 million exploit linked to North
Kelp DAO announced that it has finished the operational phase of its rsETH recovery plan, restoring full token functionality more than five weeks after a $293 million exploit tied to North Korea’s Lazarus Group [2]. The protocol transferred the last tranche of 20,373.7 rsETH to the LayerZero contract that manages cross‑chain token operations, marking the final step needed to re‑back the token after the April 18 breach.
Key takeaways
Kelp DAO’s latest update, posted on X, confirmed that the final batch of rsETH was sent to the LayerZero smart contract responsible for token locking, minting, burning and release across chains. This move follows an earlier transfer of 25,000 rsETH on May 13 that allowed withdrawals and bridging to resume. With minting, redemption and reward functions now operating normally, the protocol says rsETH is fully backed again [2].
The exploit, which occurred on April 18, siphoned 116,500 rsETH from Kelp’s bridge infrastructure, translating to a $293 million loss. Attackers immediately used the stolen rsETH as collateral on Aave, borrowing wrapped Ether and leaving nearly $190 million in bad debt across Aave’s markets. Although Aave’s total value locked fell sharply—from over $26 billion to under $14 billion—recent governance actions have restored borrowing against wrapped Ether on several Aave V3 deployments [2].
Legal battles continue over the roughly 30,765 ETH that the Arbitrum Security Council froze on April 21. Families pursuing terrorism‑related judgments against North Korea argue the assets are tied to Lazarus Group activity, while Aave contends that no court has formally attributed the exploit to North Korean actors and that the frozen assets belong to affected users [2]. Additionally, Kelp DAO’s relationship with LayerZero remains strained; the protocol announced a migration to Chainlink’s Cross‑Chain Interoperability Protocol to bolster bridge security, a claim that LayerZero’s co‑founder Bryan Pellegrino has disputed [2].
The completion of Kelp DAO’s rsETH recovery demonstrates how coordinated DeFi initiatives can mitigate the damage from large‑scale exploits, but the episode also highlights persistent vulnerabilities in cross‑chain infrastructure. The ongoing legal disputes over frozen ETH underscore the challenges of attributing cyber‑theft to state‑linked actors and determining rightful ownership of recovered assets. As Kelp DAO transitions to a new bridge solution, the broader DeFi ecosystem will watch closely to see whether enhanced security measures can prevent similar attacks and restore confidence among users and lenders.
Coverage is mostly measured — 105 of 109 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Jun 1, 2026 · How we report
Members submit proposals that are voted on using token‑based voting; if the proposal meets the required threshold, the associated smart contract executes the decision automatically.
DAOs provide decentralization of authority, transparent voting, and enable global participation without a central leader.
DAOs can be vulnerable to security exploits in their smart contracts, may experience slow decision‑making, and require members to be educated on the voting process.