# KelpDAO Loses $292M in 2026 DeFi Bridge Hack

**Published:** 2026-05-28T11:06:23.000Z  
**Topic:** Arbitrum  
**Sentiment:** bearish  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/a9a4072b-ce01-4bb1-8c18-61f1d96c197b

A $292 million exploit on KelpDAO using a compromised LayerZero bridge triggered a liquidity crisis, draining billions from DeFi protocols like Aave.

In April 2026, liquid restaking protocol KelpDAO suffered the largest decentralized finance (DeFi) exploit of the year, losing approximately $292 million in a sophisticated attack on its cross-chain bridge [1]. The incident, attributed by LayerZero to the North Korean-linked TraderTraitor subgroup, involved compromising remote procedure call (RPC) nodes to trick a single verifier into releasing 116,500 rsETH tokens [1][2]. This theft triggered a broader liquidity crisis, resulting in billions of dollars in withdrawals across the DeFi ecosystem [1].

**Key takeaways**
*   KelpDAO lost $292 million after an attacker exploited a single-verifier configuration on its LayerZero bridge [1].
*   The attacker used compromised RPC nodes and a DDoS attack to forge data and bypass security checks [1].
*   Depositing stolen rsETH as collateral on Aave allowed the attacker to borrow roughly $236 million in other assets [2].
*   The exploit caused a bank run, with over $13 billion withdrawn from DeFi protocols within 48 hours [1].

## Bridge Configuration and Node Manipulation
KelpDAO utilized a bridge built on LayerZero’s messaging infrastructure to move its rsETH token between networks, a setup that relied on a single verifier to confirm cross-chain transfer instructions [1]. On April 18, attackers compromised two RPC nodes—the servers that relay blockchain data to the verifier—and fed them forged data while accurately reporting to other monitoring systems [1]. A simultaneous distributed denial-of-service (DDoS) attack forced the verifier to fail over to the poisoned nodes, leading the system to approve a fraudulent instruction that released 116,500 rsETH to an attacker-controlled address [1]. Following the breach, a dispute arose regarding liability, with LayerZero blaming KelpDAO’s single-verifier configuration, while KelpDAO countered that this was the default setup used by roughly 40% of protocols on the network [1].

## Cascading Losses and Market Panic
After obtaining

## Sources
1. Techtarget — [The KelpDAO $292M crypto hack: What IT execs must know | TechTarget](https://www.techtarget.com/searchcio/feature/The-KelpDAO-crypto-hack-What-IT-execs-must-know)
2. Galaxy — [KelpDAO/LayerZero Hack: $290m Exploit Exposes DeFi’s Hidden Risks | Galaxy](https://www.galaxy.com/insights/research/kelpdao-layerzero-exploit-defi)

---
Cite as: TrendWatcher, "KelpDAO Loses $292M in 2026 DeFi Bridge Hack", https://www.trendwatcher.in/article/a9a4072b-ce01-4bb1-8c18-61f1d96c197b
