# Kelp DAO hack drains $293 million, highlighting DAO security risks

**Published:** 2026-07-03T19:41:52.704Z  
**Topic:** Dao Crypto  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/540064c2-ddef-4163-8fde-3af307c3b101

Kelp DAO lost $293 million (18% of rsETH supply) in a April 19 exploit. Learn how the breach works, DAO basics, and what to watch next.

A hacker siphoned roughly $293 million—about 18% of the rsETH token supply— from Kelp DAO on April 19, underscoring the security challenges facing decentralized autonomous organizations (DAOs) today [2].

| At a glance | |
|---|---|
| Amount stolen | $293 million |
| % of rsETH supply | 18 % (≈116,500 rsETH) |
| Date of exploit | April 19, 2026 |
| Catalyst | LayerZero cross‑chain message spoofing |

## What is a DAO?

A DAO (decentralized autonomous organization) is an online group that governs itself through smart contracts rather than a central hierarchy. Its primary purpose is often to manage a treasury of crypto assets, with voting power typically tied to a governance token that members stake [1]. Because the code is publicly visible on the blockchain and immutable, DAOs promise transparent, trust‑less coordination—but they also inherit the same code‑level vulnerabilities that can be exploited by attackers.

## How the Kelp DAO breach unfolded

Kelp DAO operates a liquid restaking protocol, letting users deposit staked assets such as stETH or cbETH and receive a receipt token called rsETH. To enable rsETH on more than 20 chains, Kelp maintains a bridge that holds a large reserve of the token. At 17:35 UTC on April 19, an attacker funded a wallet through the privacy tool Tornado Cash and then spoofed a message to LayerZero’s EndpointV2 contract, making the bridge believe a legitimate cross‑chain instruction had arrived. The fake message triggered the release of 116,500 rsETH—about 18 % of the total circulating supply of roughly 630,000 tokens—directly to the attacker’s address [2].

Kelp’s emergency team paused the rsETH contracts across mainnet and several L2s within an hour, freezing deposits and withdrawals to limit further damage. The incident illustrates how a single vulnerability in a cross‑chain bridge can jeopardize a large portion of a DAO’s treasury and ripple through the broader DeFi ecosystem, where rsETH is commonly used as collateral.

## What to watch

- **rsETH price and liquidity** – monitor on‑chain flows and market depth for rsETH, as the stolen tokens could be liquidated and affect price stability.  
- **LayerZero upgrades** – any announced patches or security audits of the EndpointV2 contract may reduce the risk of similar exploits.  
- **Kelp DAO governance votes** – upcoming proposals on bridge redesign or insurance mechanisms could reshape the protocol’s risk profile.

The Kelp incident shows that while DAOs enable novel, token‑driven governance, their reliance on immutable smart‑contract code creates a single point of failure. As more capital flows into DAO‑managed treasuries, the industry’s ability to secure cross‑chain bridges will determine whether the promise of decentralized finance can survive such high‑profile attacks.

## Sources
1. Cloudwards — [What is a DAO in Crypto 2026 [Decentralized Organizations]](https://www.cloudwards.net/what-is-a-dao/)
2. TheStreet.com — [Major DeFi hack becomes the largest of 2026 yet](https://www.thestreet.com/crypto/markets/major-defi-hack-becomes-the-largest-of-2026-yet)

---
Cite as: TrendWatcher, "Kelp DAO hack drains $293 million, highlighting DAO security risks", https://www.trendwatcher.in/article/540064c2-ddef-4163-8fde-3af307c3b101
