Author: Xiao Bing, Shenchao TechFlow
On April 18 at 17:35 UTC (UTC), a wallet that had been laundered using Tornado Cash sent a cross-chain message to the LayerZero EndpointV2 contract.
The meaning of this message is simple: a user on a certain chain wants to bridge rsETH back to the Ethereum mainnet. LayerZero, as designed by the protocol, faithfully transmitted the instruction. The bridging contract deployed by Kelp DAO on the mainnet also faithfully executed the release, as intended.
116,500 rsETH, worth approximately $292 million at the time, were transferred in a single transaction to an address controlled by the attacker.
The problem is that no one has ever deposited this rsETH on the other chain. This "cross-chain request" was entirely fabricated, and both LayerZero and Kelp’s bridge trusted it.
46 minutes later, Kelp’s emergency multisig finally hit the pause button. By then, the attacker had already completed the second half of the action, depositing the stolen, essentially unanchored rsETH into Aave V3 and borrowing approximately $236 million worth of wETH.
This is the largest DeFi theft of 2026 to date, exceeding the Drift protocol hack on April 1 by millions of dollars, which was carried out by hackers with North Korean ties—but what truly sends chills through the industry is more than just the amount.
How the attack occurred: Three bets placed between 17:35 and 18:28
Reconstruct the timeline.
17:35 UTC, first success. The attacker called the lzReceive function on the LayerZero EndpointV2 contract, sending a forged cross-chain packet from a wallet funded by Tornado Cash to Kelp’s bridge contract. The contract validated the packet, releasing 116,500 rsETH to the attacker’s address. Single transaction. Clean.
18:21 UTC, Kelp's emergency multisig froze the rsETH core contracts on mainnet and multiple L2s. 46 minutes since the attack.
At 18:26 and 18:28 UTC, the attacker made two additional attempts, each time sending a LayerZero packet attempting to withdraw another 40,000 rsETH (approximately $100 million). Both were reverted—the contract has been frozen—but the attacker appears to still be trying to drain the remaining liquidity.
Nearly three hours passed between the initial breach and Kelp’s public statement.
Kelp's first X post was not issued until 20:10 UTC and was phrased conservatively: Detected suspicious cross-chain activity involving rsETH; rsETH contracts on mainnet and multiple L2s have been paused. We are collaborating with LayerZero, Unichain, auditors, and external security experts to conduct a root cause analysis.
But before the official statement, ZachXBT, a blockchain detective, issued an alert on his Telegram channel before 3 PM Eastern Time, listing six wallet addresses linked to the theft and noting that the attacker’s wallets had all been funded through Tornado Cash prior to the attack. He did not name Kelp DAO, but on-chain analysts connected the addresses within just a few hours.
This was a meticulously planned operation executed on a minute-by-minute basis: pre-funded wallets that had been laundered, carefully crafted cross-chain data packets, and a sequence of attacks targeting Aave loans—each step precisely timed, like footsteps synced to a metronome.
Steal and then scam you again
If this were merely a bridge vulnerability, with 116,500 rsETH stolen and the perpetrators fleeing, it would amount to little more than a major incident in 2026. Kelp would absorb the loss, the community would digest it over a few days, and the industry would move on.
But the attackers clearly did the math. rsETH itself lacks sufficient secondary liquidity; dumping $292 million directly onto a DEX would consume a significant portion of the profits through slippage. A more elegant exit strategy would be to package these "air-dropped" rsETH as seemingly respectable collateral, then borrow truly liquid assets through lending protocols.
The attacker then took the second step: depositing the stolen rsETH into Aave V3 as collateral and borrowing a large amount of wETH.
Why is this step fatal? Because at that moment, the Aave contract was still calculating the collateral value based on the rsETH oracle price, while the reserves in the bridge had already been emptied—meaning the economic foundation of these rsETH tokens no longer existed. The lending protocol was still issuing loans as if the collateral were 100% backed, but the collateral had become a worthless check.
As a result, the attacker shifted the risk of converting funds into cash onto Aave's wETH reserve pool.
Aave V3's wETH reserve is currently absorbing bad debt. Solidity developer and auditor 0xQuit has warned depositors on X that the wETH pool is effectively impaired, and partial withdrawals can only be restored after Aave's Umbrella backup module settles the deficit.
The latest estimate for the bad debt scale is around $177 million, and this is only on the Ethereum mainnet side.
A prophesied first major test
For seasoned DeFi users, this feels familiar—during the Luna collapse in 2022, Aave V2’s Safety Module played a similar role.
But this time, Umbrella is in the spotlight—the next-generation backup system launched by Aave at the end of 2025 to replace the old Safety Module—marking its first major real-world stress test of its automated bad debt coverage mechanism.
The logic of Umbrella is straightforward: stake aWETH, aUSDC, GHO, and other aTokens into the corresponding Umbrella vaults to earn additional incentives under normal conditions, but when the corresponding asset pool experiences a deficit, these staked amounts will be proportionally slashed to cover the shortfall.
This design looks great on paper: during the first month of Aave v3.3’s operation, the total pool deficit was approximately $400, against nearly $9.5 billion in outstanding loans—a ratio so small it’s virtually negligible.
But a $177 million bad debt is on another scale entirely. For users who staked aWETH to Umbrella, this will be the first time they truly feel the weight of the phrase "bearing slashing risk." Aave's official statement has been cautious: if bad debt occurs, Aave plans to use Umbrella assets to cover any financial shortfall. However, whether the coverage will be complete, the slashing ratio, and how much principal users will lose—all these questions can only be answered after settlement is complete.
The Original Sin of Cross-Chain Bridges
More concerning is the identity of the stolen rsETH.
rsETH has been deployed on over 20 networks, including Base, Arbitrum, Linea, Blast, Mantle, and Scroll, with cross-chain transfers handled by LayerZero’s OFT standard. The rsETH drained from the bridge serves as the reserve backing all "wrapped" versions of rsETH on these networks.
This design sounds conventional at first glance: the mainnet treasury holds 1:1 reserves, and rsETH holders on L2 can theoretically redeem their tokens on the mainnet at any time. But this mechanism relies on the premise that the treasury actually has the funds.
The treasury is now 18% empty. Approximately 18% of the circulating supply of Kelp’s rsETH lost its corresponding reserve overnight.
This creates a feedback loop: when holders on L2 panic and redeem, pressure is transmitted to the unaffected Ethereum supply side, potentially forcing Kelp to unwind re-staking positions to meet withdrawal requests.
Restaking withdrawal is not a one-click process. EigenLayer’s withdrawals have a delay period, and the underlying validators have a queue for exit. If rsETH holders on L2 collectively rush to the redemption window, Kelp may not have enough time to prepare the mainnet’s repayment resources.
This is a fundamental risk of the bridge reserve model: if the mainnet reservoir fails, the water pressure collapses across all downstream channels. Every rsETH holder on every L2 is now facing the same choice: run first, or trust Kelp to cover the losses?
Panic swept through the entire DeFi lending sector within hours.
The rsETH markets for Aave V3 and V4 have been frozen; new deposits and lending pathways based on rsETH have been disabled.
SparkLend and Fluid are following up with a freeze on the rsETH market.
Although Ethena stated it has no exposure to rsETH and maintains over 101% collateralization, it has temporarily paused its LayerZero OFT bridge from the Ethereum mainnet as a precautionary measure, with the pause expected to last approximately six hours. This response is intriguing: even participants with no direct exposure are halting LayerZero-related bridges.
Lido Finance has paused new deposits into its earnETH product (due to rsETH exposure), while emphasizing that stETH and wstETH are unaffected, and Lido's core staking protocol is unrelated to this event.
Upshift has suspended deposits and withdrawals for the High Growth ETH and Kelp Gain vaults.
This list is still growing.
DeepChain commentary: The path to DeFi security is long
As of the writing of this article, Kelp DAO’s root cause analysis is still ongoing. How much of the stolen rsETH can be recovered through the security team or white hat negotiations? Can Aave’s Umbrella withstand this wave of bad debt? Will rsETH holders on L2 trigger a bank run? Can AAVE and rsETH prices stabilize before the end of the weekend?
But some issues have already become apparent.
For example, can LRT continue to serve as eligible collateral for lending protocols?
Liquid Restaking Token (LRT) was the darling of the Ethereum ecosystem in the previous cycle. EigenLayer launched the narrative of “earn multiple layers of yield from a single ETH,” and protocols like Kelp, ether.fi, and Puffer industrialized this narrative. The end result: LRTs were added to the collateral whitelist by major lending protocols as structured assets.
This decision is based on the assumption that LRT's anchoring mechanism is sufficiently robust, and that the layered nesting risks of the underlying assets can be adequately modeled and isolated at the smart contract level.
The Kelp event shattered this assumption in just an afternoon. LRT’s risks stem not only from its underlying smart contracts, but also from its cross-chain distribution architecture; not only from a single protocol, but from every dependency it has with EigenLayer, LayerZero, and Aave. Each piece of the DeFi Lego set looks safe on its own, but when assembled, the risks multiply rather than add up.
Over the coming months, all lending protocols that still list LRTs as high-grade collateral must reassess their risk parameters. Supply caps will be reduced, liquidation buffers will be widened, and some protocols may delist them entirely.
The moat of DeFi has always been called "composability," but this incident reminds everyone: composability is a double-edged sword. The network effect you take pride in becomes an amplifier in the hands of attackers.
The attackers had planned their exit strategy in advance—not just to steal, but to weaponize DeFi composability. The more tightly interconnected and composable the protocols are, the broader the attack surface becomes, and the more financial LEGO pieces they can leverage.
DeFi security still has a long way to go.

