KelpDAO Hack Triggers $13 Billion DeFi Wipeout and Aave Crisis
CoinCentral·60-word summary·1 min read
A $292-293 million exploit on KelpDAO’s bridge led to a $13.21 billion drop in DeFi total value locked over 48 hours. Hackers stole 116,500 rsETH tokens and used them as fake collateral on Aave, incurring approximately $195 million in bad debt. Aave’s TVL plummeted from $26.4 billion to $18.6 billion, triggering a major crisis in the DeFi sector.
The Strait of Hormuz crisis caused an 8% surge in crude oil prices, highlighting vulnerabilities in global oil supply chains. This development, reported on April 20, 2026, raises concerns over prolonged market volatility and economic uncertainty. The crisis underscores the geopolitical risks impacting energy markets, which could influence broader financial stability and investment strategies.
On Friday, ARK Invest, led by Cathie Wood, bought 26,161 Netflix shares worth approximately $2.5 million after a nearly 10% post-earnings drop. The firm also sold $1.21 million in Circle shares amid a class-action lawsuit related to the Drift Protocol exploit and offloaded $1.36 million in bullish crypto stocks despite Bitcoin's rise.
The AAVE DeFi protocol suffered a major exploit, causing a $7 billion drop in total value locked (TVL) and a 15% price decline. The security breach raises concerns about DeFi protocol vulnerabilities, prompting increased scrutiny from investors and developers. The incident underscores the importance of robust security measures in decentralized finance platforms to prevent future exploits.
KelpDAO, a liquid restaking protocol backed by YZi Labs, suffered a $290 million hack via LayerZero’s cross-chain bridge. LayerZero blames North Korea’s Lazarus Group and KelpDAO’s poor security practices for the exploit, which drained rsETH and risks contagion to protocols like Aave. The attack highlights security risks in cross-chain DeFi protocols.
Microsoft has issued emergency out-of-band updates to address critical issues affecting Windows Server systems following the April 2026 security patches. The fixes aim to resolve vulnerabilities that could be exploited by attackers, ensuring system stability and security for enterprise users. Microsoft recommends all affected users apply these updates immediately to mitigate risks.
Iran has labeled a recent ship attack as an act of aggression, amid escalating diplomatic tensions with the United States. The incident, which has heightened skepticism about US-Iran negotiations, threatens to hinder diplomatic progress. The rising hostility and aggressive rhetoric between the two nations are fueling concerns over potential conflicts and complicating efforts for resolution.