Kelp DAO Restores rsETH Tokens After $293 Million Hack
In April 2026 a sophisticated RPC‑poisoning attack attributed to the North Korean Lazarus Group stole roughly $293 million from Kelp DAO’s liquid restaking token rsETH. The exploit forged data on the LayerZero OFT bridge, causing illicit minting of about 117,000 rsETH that were used as collateral on Aave and other platforms, pushing the token’s peg to a low of $2,800.
Kelp DAO and Aave have now completed the “exploit‑burn” on Arbitrum, destroying the attacker’s rsETH holdings, and have begun a coordinated refill of 117,132 rsETH (about $278 million) over the next two weeks. The refill will be executed via a multi‑signature wallet shared between the Aave Recovery Guardian and Kelp’s internal security wallet, with withdrawals slated to reopen within 24 hours of the first tranche.
Security has been hardened: bridge transactions now require validation by four independent parties, confirmation across 64 blocks, and risky L2‑to‑L2 routes have been disabled while the bridge migrates to Chainlink’s cross‑chain protocol. Total value locked in Kelp fell to $1.55 billion from a peak above $2 billion, but rsETH remains fully collateralised across mainnet and layer‑2 networks.
The recovery is described as one of the most extensive in DeFi history, aiming to restore normal deposit, withdrawal, bridging and redemption operations for rsETH.