# Kelp DAO hack wipes $292 M, highlights DeFi security gaps

**Published:** 2026-05-02T13:03:32.000Z  
**Topic:** Dao Crypto  
**Sentiment:** bearish  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/347c1d71-d56e-468e-af8c-7c3469636340

Kelp DAO exploit on April 18 2026 stole $292 M, exposed $4.5 B of vulnerable assets and spurred calls for institutional‑grade safeguards.

The $292 million Kelp DAO exploit on April 18 2026 forced the DeFi sector to confront its weakest links just as Wall Street firms such as Apollo Global Management and BlackRock deepen on‑chain exposure【1】.  

| At a glance | |
|---|---|
| Hack value | $292 M |
| Tokens minted | 116,500 unbacked rsETH |
| Borrowed on Aave | $230 M |
| At‑risk LayerZero assets | $4.5 B |

## How the attack unfolded  
The attacker targeted Kelp DAO’s liquid restaking token, rsETH, by exploiting a misconfigured LayerZero bridge setting. By minting 116,500 rsETH without collateral, the hacker used the fake tokens to borrow roughly $230 M from the Aave lending platform before the breach was detected【3】. CoinGecko’s analysis notes that nearly half of all active LayerZero‑powered applications remain vulnerable, putting more than $4.5 B of market value at immediate risk【3】.  

## Industry reaction and the push for stronger safeguards  
The breach coincided with Apollo Global Management’s partnership with Morpho to support lending markets and BlackRock’s tokenized money‑market fund debut on Uniswap, underscoring the growing institutional appetite for on‑chain finance【1】. Security specialists argue that DeFi’s “zero‑trust” architecture must become baseline, not optional, with tighter multi‑signature controls, timelocks on governance actions, and robust collateral frameworks【1】.  

## What to watch  
- **LayerZero bridge updates** – monitor announcements from the LayerZero team for patches that could reduce the $4.5 B exposure.  
- **Aave borrowing limits** – watch for changes to collateral requirements that may prevent similar synthetic borrowing attacks.  
- **Institutional on‑chain moves** – track further partnerships from Apollo, BlackRock or other firms that could signal confidence or pressure for higher security standards.  

The hack proves that while DeFi continues to attract traditional finance capital, its security foundations must evolve before larger pools of institutional money can be safely absorbed.

## Sources
1. Mademoneytoday — [The $292M crypto hack exposed DeFi's weak spots. Here's ...](https://mademoneytoday.com/news/the-292m-crypto-hack-exposed-defi-s-weak-spots-here-s-what-must-change-insiders-say)
2. Activistpost — [The $292M crypto hack exposed DeFi's weak spots. Here’s what must change, insiders say - Activist Post](https://www.activistpost.com/the-292m-crypto-hack-exposed-defis-weak-spots-heres-what-must-change-insiders-say/)
3. Crowdfund Insider — [DeFi Hack Analysis : Billions in Crypto Assets Left Exposed After Kelp DAO Exploit](https://www.crowdfundinsider.com/2026/04/275229-defi-hack-analysis-billions-in-crypto-assets-left-exposed-after-kelp-dao-exploit/)

---
Cite as: TrendWatcher, "Kelp DAO hack wipes $292 M, highlights DeFi security gaps", https://www.trendwatcher.in/article/347c1d71-d56e-468e-af8c-7c3469636340
