📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

This Hack Just Broke DeFi… And Exposed Everything

Coin Bureau15:06

Transcription

On the 18th of April 2026, at approximately 1735 UTC, an attacker called a single function on a layer zero contract and walked away with 116,500 RS ETH worth approximately $293 million from Kelp DAO, making this the largest DeFi exploit of the year so far.

Within minutes, that stolen collateral had already been weaponized across Ave, Compound, and Oiler to borrow another quarter of a billion dollars in clean ETH. And within hours, panicked users had stripped over $6 billion of liquidity from Ave alone. Withdrawals had been frozen across the entire ecosystem. And more than $10 billion from DeFi's overall TVL had been erased.

Yep, more money has been vaporized. More bad headlines have been generated. And guess what? A foundational flaw in DeFi's architecture has been laid bare for good measure. My name is Guy and you're watching the Coin Bureau. Let's kick off the postmortem by looking at the asset class at the center of this disaster.

Kelp DAO is a liquid restaking protocol built on top of Eigen Layer, and its flagship token RS ETH represents ETH that has been deposited, staked, and then restaked across additional security services to generate layered yield. Now, liquid restaking tokens or LRTs exploded across 2024 and 2025 as the most aggressive yield primitive in DeFi, attracting billions in deposits on the assumption that the underlying ETH collateral could always be recovered by the user.

The 116,500 RSE drained from Kelp's bridge represented roughly 18% of the entire RS ETH circulating supply. And crucially, every single token was meant to be backed one for one by ETH sitting in the protocol's reserves. To move RS ETH between the Ethereum mainnet and other chains like Uni Chain, Kelp deployed an omni chain fungible token or OFT adapter built on Layer Zero, the dominant cross-chain messaging protocol in the space.

Now, the integrity of that bridge depends entirely on a component called the decentralized verifier network or DVN, a set of independent validators tasked with confirming that whatever happens on the source chain did actually happen before the destination chain releases any tokens. And this is where the entire incident actually begins.

You see, Layer Zero allows protocols to configure how many DVN signatures are required to validate a cross-chain message, and the framework permits configurations all the way down to a single signature from one single validator. Kelp DAO, despite securing close to a third of a billion dollars worth of bridged collateral, had configured its bridge with a one-of-one DVN setup. So, put simply, the protocol delegated the entire security of the bridge to one signing key controlled by one entity.

Slowmist, the security firm that performed the postmortem, described this configuration as the weakest security level the Layer Zero framework permits, and the red flag had been there in plain sight for over a year. References in Ave governance forums dating back to January 2025 reportedly flagged this exact single validator risk when RSE was first being evaluated as collateral. The warning was acknowledged, debated, and then ultimately ignored by the very protocols that would later feel the consequences.

Now, the attack itself unfolded with surgical precision. Roughly 10 hours before the exploit, the perpetrator funded nine separate operational wallets through Tornado Cash using the standard 1 ETH mixing pool, depositing approximately 0.0978 ETH into each address as gas. At the moment of execution, the attacker first called commit verification on the DVN verifier contract using the compromised signing key, planting a forged attestation that claimed a legitimate deposit had occurred on Uni Chain.

Seconds later, they invoked the LZ receive function on Layer Zero's endpoint v2 contract at Ethereum block 24,982,85, delivering a payload that spoofed a deposit instruction from Kelp's peer contract on the source chain. The mainnet adapter, seeing what appeared to be a fully attested cross-chain message, executed exactly as designed and released the entire stolen position from escrow to the attacker's address.

Now, no ETH was ever locked or burned anywhere on Uni Chain. The tokens were, for all practical purposes, conjured directly out of thin air. As the developer 0xngmi summarized on X, "One signature and the entire stolen tranche of RS ETH materialized on Ethereum and the smart contracts themselves were never broken because the verification logic was the flaw."

You might assume that an attacker sitting on this scale of freshly minted unbacked tokens would immediately race to a decentralized exchange, dump the supply, and convert their bounty before anyone could react. However, that assumption entirely misunderstands the level of sophistication on display here. Dumping the position on the open market would have crashed the price within minutes, signaling the exploit to every monitoring tool in the industry and generating catastrophic slippage that would have eaten a significant chunk of the take.

No, instead the attacker did something far more devastating. They deposited the entire stolen position as collateral into Ave v3, Ave v4, Compound v3, and Oiler simultaneously. And against that collateral, they borrowed over $236 million in wrapped ETH or WETH directly from the lending pools. So, clean, liquid, fully fungible ETH walked out the front door while the RS ETH positions were left behind as uncollectible bad debt for the protocols to absorb. And this pattern of laundering stolen illiquid collateral through lending markets is rapidly becoming the signature playbook of sophisticated DeFi exploits. And it converts a theft of a fragile asset into clean capital that can be moved anywhere on-chain.

Kelp DAO's emergency multisig executed the pause all function at 18:21 UTC, exactly 46 minutes after the first malicious transaction settled, freezing the deposit pool, the withdraw module, the oracle, and the RS ETH token across mainnet, Arbitrum, Base, and Scroll. And that decision proved decisive. At 18:26 and again at 18:28, the attacker attempted two follow-up drains of 40,000 RS ETH, additional positions worth roughly $100 million a piece. Both transactions reverted against the active pause, blocking what would have been an additional couple of hundred million in losses.

ZackXBT publicly flagged the Tornado Cash funding pattern shortly after, while the security firm Cyvers traced the contagion path and warned that this was no longer just a protocol exploit but had immediately metastasized into a cross-protocol contagion event. The challenge, as Cyvers put it, is no longer simply preventing exploits at the contract level, but understanding how violently they can cascade across integrated protocols. And the cascade is the real story here.

Ave's governance had previously approved RS ETH as collateral with a loan-to-value ratio reported at approximately 93%, a buffer of 7 percentage points between the borrowed amount and a position becoming undercollateralized. Under normal market conditions, that thin margin is defensible because liquidators can step in and seize collateral before bad debt accumulates. But when the underlying backing of the asset evaporates entirely because the bridge that minted it has been compromised, no liquidator on Earth has any economic incentive to seize tokens worth a fraction of the borrowed sum. The buffer collapses instantly, and the protocol is left with the deficit.

Mark Zella of the Avechan Initiative, one of the most prominent governance voices in the entire ecosystem, immediately took to X, urging users to withdraw their WETH from Ave v3 core now and ask questions later. The Solidity auditor 0xquit posted moments later that WETH on Ave was, in his words, "finished" and that anyone still inside should withdraw if they could, but it was likely already too late.

And what followed was a textbook bank run. Between $5.4 and $6.6 billion in ETH was pulled from Ave in a matter of hours, pushing pool utilization to 100% and temporarily freezing legitimate withdrawals for users who had nothing whatsoever to do with RSE. Ave's TVL collapsed from $26.4 billion to roughly $20 billion, vaporizing approximately $6 billion in a single trading session. Bad debt estimates across Ave alone landed somewhere between $177 and $200 million, with the figure climbing past a quarter of a billion once Compound and Oiler exposures were included.

The Ave token itself opened the day at almost $115 and closed the following session at just over $91, a drop of over 20% across two trading days against an ETH market that fell less than 3% in the same window. Sparklend, Fluid, and Upshift all froze their RS ETH markets. Lido poured deposits into its Earn ETH product, and Athena halted its own Layer Zero bridges as a purely precautionary measure, even though it had no direct exposure. Total DeFi TVL bled out by more than $10 billion in roughly 24 hours.

And amidst all of this, Justin Sun produced one of the most surreal performances of the entire incident. The Tron founder withdrew 65,584 ETH from Ave during the height of the panic, an amount valued at approximately $154 million, materially contributing to the very utilization spike that locked other users out of the protocol. Then, while that withdrawal was still settling, he published a public message addressed directly to the attacker on X, asking how much they wanted and suggesting it simply was not worth sacrificing both Ave and Kelp DAO. Yes, one of the largest single drains on the liquidity pool was simultaneously positioning himself as the one to mediate the crisis. Only in crypto, folks. Only in crypto.

And this brings us to what the 18th of April actually exposed. The mechanism that was exploited here was not a smart contract bug, not a front-end vulnerability, not a flash loan attack, and not a governance hijack. The mechanism was an architectural choice to delegate the security of close to a third of a billion dollars in collateral to a single signing key, layered beneath an entire stack of lending protocols that had agreed to accept the resulting tokens with virtually no safety buffer.

Every single liquid restaking token currently sitting in a lending market across DeFi inherits the security of the bridge that minted it. Every single bridge built on the OFT standard with a minimal DVN configuration represents a rehearsal of this exact exploit waiting for a sufficiently motivated attacker to materialize. Every single lending protocol that has approved an LRT as collateral with a thin safety margin has implicitly assumed that the underlying redemption guarantee will hold under all market conditions, including the condition where the redemption infrastructure itself has been compromised.

The composability that makes DeFi powerful, the ability for one protocol's output to seamlessly become another protocol's input, is the exact same property that turns a single bridge failure into a multi-billion dollar ecosystem-wide rupture in under 4 hours.

So, April 2026, which isn't even over yet as I record this, will go down as DeFi's worst month of the year, with the Drift Protocol exploit on the 1st of April having already extracted $285 million from the Solana ecosystem at the hands of North Korean operators. Combined losses in less than three weeks have now eclipsed $600 million, and the structural conditions that produced both events remain entirely unchanged.

Kelp DAO has opened a 24-hour white hat negotiation window with the attacker, the now standard ritual, where protocols offer a percentage of the take in exchange for the return of the bulk of the funds. Whether that negotiation produces a recovery or simply an embarrassing silence remains to be seen. But well, don't hold your breath.

But the deeper consequence of this attack is that the implicit safety assumptions underpinning the entire LRT as collateral edifice have been publicly falsified, and no amount of governance patching can restore the trust that was incinerated on the afternoon of the 18th of April. The surviving protocols may well emerge structurally stronger from this stress test with tighter LTV caps, mandatory multi-DVN configurations, and far more conservative collateral onboarding processes. But the cost of that lesson has been borne almost entirely by the depositors who believed the system was already safe.

So, will DeFi learn its lessons from this disaster and come back stronger, or is another cluster [expletive] just a matter of time? Let me know your thoughts down in the comments. And if you want to understand exactly how the Drift Protocol exploit earlier this month set the stage for what we just witnessed, then you can check out our full deep dive on that incident right over here. Okay, thank you all so much for watching, and I'll see you again soon, hopefully without yet another video explaining yet another DeFi exploit. This is Guy signing.