$280M KelpDAO exploit via LayerZero bridge shakes DeFi markets
Crypto Briefing·60-word summary·1 min read
A $280 million exploit on KelpDAO via the LayerZero bridge has raised concerns over DeFi security vulnerabilities. The incident, which occurred recently, has impacted market confidence and liquidity, highlighting systemic risks within DeFi infrastructure. The exploit underscores the need for enhanced security measures in cross-chain protocols to prevent future breaches.
DeFiLlama co-founder suggests three options to address the $293 million KelpDAO hack fallout. If losses are distributed among KelpDAO users, they would face an 18.5% loss, creating a $76 million gap. Aave could cover this shortfall by selling assets or taking on debt, highlighting ongoing challenges in DeFi security and risk management.
Nearly $1 billion in Bitcoin ETF inflows has strengthened the bullish outlook for the crypto market. The news comes amid concerns over a recent DeFi hack involving Kelp, which has heightened security jitters in the sector. The inflows highlight growing institutional interest, despite ongoing security challenges in decentralized finance platforms.
Bitcoin declined from recent highs on April 20, 2026, amid concerns over a CME futures gap and fallout from a DeFi hack that impacted altcoins. Traders also faced macroeconomic pressures, leading to a cautious market sentiment. The drop reflects ongoing security concerns and the influence of external factors on Bitcoin’s price stability.
LayerZero announced that Kelp’s DVN setup caused the $290 million exploit on Aave in April 2026. The incident has raised questions about which protocol will cover the losses, as investors seek clarity on the security breach and potential recovery measures. The exploit highlights ongoing security concerns within the DeFi ecosystem.
LayerZero has linked a $292 million exploit of Kelp DAO’s rsETH bridge to North Korea’s Lazarus Group. The attack exploited a single-verifier configuration, which LayerZero had previously warned against. The incident highlights ongoing security vulnerabilities in cross-chain bridges, with Lazarus Group suspected of orchestrating the theft on April 20, 2026.
LayerZero has attributed the recent Kelp DAO exploit to North Korean hacking group Lazarus Group. The company suggests Lazarus was responsible for the attack, which resulted in significant losses for Kelp DAO. The incident highlights ongoing security threats from state-sponsored cybercriminals targeting DeFi platforms, with no specific amount disclosed. The attack occurred in April 2026.