Start now →

The $292 million Kelp exploit: how it happened, and what it means for DeFi

By Krisztian Sandor · Published April 19, 2026 · 6 min read · Source: CoinDesk
DeFiWeb3RegulationSecurity
FinanceShare this articleX (Twitter)LinkedInFacebookEmail

The $292 million Kelp exploit: how it happened, and what it means for DeFi

2026 is shaping up to be DeFi's "worst year in terms of hacks," Ledger's CTO said, as the Kelp exploit shows how a single point of failure can cascade across systems.

By Krisztian Sandor|Edited by Nikhilesh De Apr 19, 2026, 10:27 p.m. Make preferred on
Glasses in front of monitors with code (Kevin Ku/Unsplash)
(Kevin Ku/Unsplash)

What to know:

A roughly $292 million exploit over the weekend has rattled the crypto industry, exposing vulnerabilities in decentralized finance (DeFi) infrastructure and raising concerns about knock-on effects across lending protocols.

While investigations are still ongoing, early analysis suggests the attack centered on Kelp’s rsETH token — a yield-bearing version of ether (ETH) — and the mechanism used to move assets between blockchains.

The attacker appears to have manipulated that system to create large amounts of tokens without proper backing, then quickly used them as collateral to borrow and drain real assets from lending markets, mostly from Aave AAVE$90.31, the largest decentralized crypto lender.

The incident is the latest blow to DeFi, happening only a couple weeks after the $285 million exploit of Solana-based protocol Drift, further denting investor trust in the nearly $90 billion crypto sector.

How the attack worked

At a high level, the exploit targeted a LayerZero bridge component — a piece of infrastructure that enables assets to move across different blockchains, Charles Guillemet, CTO of hardware wallet maker Ledger, told CoinDesk in a note.

Bridges typically work by locking assets on one chain and minting equivalent tokens on another. That process depends on a trusted entity — often called an oracle or validator — to confirm deposits.

In this case, Kelp effectively acted as that verifier. According to Guillemet, the system relied on a single-signer setup, meaning just one entity could approve any transactions.

"It seems the attacker was able to sign a message … allowing him to mint large amount of rsETH," he said. He added that it remains unclear how that access was obtained.

Michael Egorov, founder of Curve Finance, pointed to the same weakness in the system's configuration.

"Things can happen when you trust one single party — whoever that would be."

That setup allowed the attacker to effectively create unbacked tokens, even though no corresponding assets were locked on the source chain.

Once minted, the tokens were quickly deployed. The attacker "immediately deposited them in lending protocols mostly Aave to borrow real ETH against," Guillemet explained.

That maneuver shifted the problem from a single exploit into a broader market issue. DeFi lending platforms are now left holding collateral that may be difficult to unwind, while valuable and liquid assets are already drained.

"Aave was left with rsETH which cannot be really sold and maxborrowed [sic] ETH, so no one can withdraw ETH," Curve's Egorov said.

As a result, Aave and other lending protocols may be sitting on hundreds of millions of dollars in questionable collateral and bad debt, he warned, raising concerns of a potential "bank run" dynamic as users rush to withdraw funds.

Aave saw about a $6 billion drop in assets on the protocol as users yanked their assets following the incident. The token associated with the protocol was down about 15% over the past 24 hours' trading.

What we still don’t know

Key questions remain around how the validator was compromised. The system relied on LayerZero’s official node, raising uncertainty over whether it was hacked, misconfigured or misled.

"Was it hacked? Was it fooled? We don't know," Egorov said.

The attacker's identity is also unknown, though Guillemet said the scale of the attack suggests a sophisticated actor.

"Clearly not some script kiddies," he said.

Big blow for trust in DeFi

Beyond the immediate losses, the exploit the episode serves as another reminder that as DeFi grows more interconnected, failures in one layer can quickly cascade across the system.

Egorov argued that non-isolated lending models, where assets share risk across pools, amplify the impact of such events.

He also pointed to shortcomings in how new assets are onboarded to lending platforms, saying configurations like Kelp's 1-of-1 verifier setup should have been flagged earlier.

However, Egorov said there's a silver lining. "Crypto is a harsh environment which no bank would have survived — yet we are working with that," he said. "I think DeFi will learn from this incident and become stronger than before."

Still, even as incidents like this lead to protocol upgrades and redesigns, they also chip away investor confidence in the broader DeFi sector.

"All in all, the trust into DeFi protocols is eroded by this kind of event," Guillemet said.

"And 2026 will most likely be the worst year in terms of hacks, again," he added.

Read more: 'DeFi is dead': crypto community scrambles after this year's biggest hack exposes contagion risks

DeFiHackEthereum News

More For You

Stablecoins can help businesses turn costs into revenue, Paxos Labs cofounder says

By Krisztian Sandor|Edited by Nikhilesh De7 hours ago
Digitally altered photo of a dollar bill (Ryan Quintal/Unsplash, Modified by CoinDesk)

Firms using stablecoins can reshape margins by cutting costs, unlock credit and earn yield, but not every company needs to issue a token, Paxos Labs' Chunda McCain said.

What to know:

Read full storyLatest Crypto News Consensus is coming soon to a Miami near you. (Nikhilesh De/CoinDesk)

Previewing Consensus' Policy Summit: State of Crypto

4 hours ago
btcproblemsolving

Web3 VCs have a differentiation problem

4 hours ago
(Getty Images)

'DeFi is dead': crypto community scrambles after this year's biggest hack exposes contagion risks

5 hours ago
Digitally altered photo of a dollar bill (Ryan Quintal/Unsplash, Modified by CoinDesk)

Stablecoins can help businesses turn costs into revenue, Paxos Labs cofounder says

7 hours ago
Aave Labs founder Stani Kulechov and Ethena founder + CEO Guy Young (Margaux Nijkerk/ CoinDesk)

Aave sees $6 billion deposit drop as Kelp hack exposes structural risk for DeFi lender

8 hours ago
Bitcoin slides back into familiar range (Shutterstock)

RaveDAO's RAVE token collapses 90% in a day as exchange probes widen

8 hours ago
Top StoriesCypher Protocol suffers exploit (Clint Patterson/Unsplash)

2026's biggest crypto exploit: $292 million gets drained from Kelp DAO with wrapped ether stranded across 20 chains

Apr 18, 2026
People with a laptop in front of a whiteboard (Kaleidico/Unsplash)

Binance and Bitget to probe RAVE’s 4,500% token surge as claims of insider-orchestrated rally grow

Apr 18, 2026
Strategy Executive Chairman Michael Saylor on CoinDesk Television

Why Michael Saylor's Strategy decided to make STRC's dividend bi-monthly

Apr 18, 2026
A bulk carrier shrouded in mist awaits entry to the Strait of Hormuz

Bitcoin falls back to $76,000 as Iran shuts Hormuz again

Apr 18, 2026
Strategy Executive Chairman Michael Saylor at the Digital Asset Summit in New York City on March 20, 2025. (Nikhilesh De)

Strategy proposes semi-monthly dividends on its popular STRC preferred stock

Apr 17, 2026

In this article

AAVEAAVEAAVE$90.3112.89%
This article was originally published on CoinDesk and is republished here under RSS syndication for informational purposes. All rights and intellectual property remain with the original author. If you are the author and wish to have this article removed, please contact us at [email protected].

NexaPay — Accept Card Payments, Receive Crypto

No KYC · Instant Settlement · Visa, Mastercard, Apple Pay, Google Pay

Get Started →