Summary of "This Hack Just Broke DeFi… And Exposed Everything"

High-level summary

On 18 Apr 2026 (~17:35 UTC) an attacker exploited a bridge/verification configuration to mint 116,500 RS‑ETH (≈ $293M) from Kelp DAO. The attacker then used that unbacked liquid restaking token (LRT) as collateral across lending markets to borrow >$236M in wrapped ETH (WETH), converting fragile, illiquid stolen tokens into clean capital. The incident froze withdrawals, triggered massive liquidity outflows and contagion across DeFi, and exposed a structural risk in using LRTs as collateral.

Assets, tickers and instruments mentioned

Attack methodology (step‑by‑step)

  1. Recon / configuration
    • Kelp’s bridge was configured with a one‑of‑one DVN (single validator signing key) despite large bridged collateral.
  2. Staging
    • Attacker funded nine operational wallets via Tornado Cash, depositing ~0.0978 ETH to each for gas ~10 hours prior.
  3. Forged attestation
    • Using a compromised signing key, attacker called commit verification on the DVN verifier contract and planted a forged attestation (claiming a deposit on a source chain).
  4. Cross‑chain spoof
    • Invoked LZ_receive on the LayerZero endpoint v2 at Ethereum block ~24,982,85 with a payload spoofing a Kelp deposit.
  5. Release
    • The OFT adapter accepted the attestation and released 116,500 RS‑ETH to the attacker — these tokens were never backed by actual ETH on the source chain.
  6. Laundering via lending
    • Attacker deposited RS‑ETH as collateral into lending pools (RV v3, RV4, Compound V3, Oiler) and borrowed >$236M WETH.
  7. Follow‑up attempts
    • Attacker attempted two additional drains (~40,000 RS‑ETH each) but were blocked when Kelp paused activity.

Key timeline and timestamps

Key numbers and market impact

Root cause / structural issues

Protocol responses, defenses and effects

Lessons, recommended mitigations and likely industry changes

Cautions and warnings

Disclosures / disclaimers

Presenters and sources referenced

Category ?

Finance


Share this summary


Is the summary off?

If you think the summary is inaccurate, you can reprocess it with the latest model.

Video