KelpDAO Migrates rsETH to Chainlink After $292 Million LayerZero Exploit
On 18 April 2026, KelpDAO’s cross‑chain bridge built on LayerZero was attacked, resulting in the loss of about US$292 million (116,500 rsETH). Chainalysis linked the exploit to North Korea’s Lazarus Group, describing it as an off‑chain infrastructure attack that fed false data to a single‑verifier setup.
KelpDAO blamed LayerZero for allowing the vulnerable configuration, saying the company failed to warn about the risk. LayerZero countered that Kelp had deviated from its recommended multi‑verifier model, and that the default settings are secure.
In response, KelpDAO announced it will migrate its restaked ETH token (rsETH) to Chainlink’s Cross‑Chain Interoperability Protocol (CCIP), which uses 16 independent node operators to validate transactions. The protocol change aims to relaunch rsETH transfers securely after a second attempted theft of 40,000 rsETH was blocked.
The breach caused broader DeFi market stress, with Aave V3 liquidity dropping from US$9.77 billion to US$5.75 billion within 29 hours. About US$71 million of crypto tied to the attack is now the subject of a New York federal court dispute.