DeFi in Crisis: Kelp DAO’s $292M Exploit Shakes Cross-Chain Security in 2026

Kelp DAO suffered a $292M exploit on April 18, 2026, due to a critical LayerZero bridge flaw, marking one of the largest DeFi hacks of the year.

Share
DeFi in Crisis: Kelp DAO’s $292M Exploit Shakes Cross-Chain Security in 2026

Hero illustration for article: DeFi in Crisis: Kelp DAO’s $292M Exploit Shakes Cross-Chain Security in 2026

Summary

  • Kelp DAO suffered a $292M exploit on April 18, 2026, due to a critical LayerZero bridge flaw, marking one of the largest DeFi hacks of the year.
  • DeFi losses in 2026 have already surpassed $750M by mid-April, with April alone seeing $606M drained across multiple exploits.
  • The incident exposes urgent vulnerabilities in cross-chain protocols, pushing the industry to prioritize robust security measures.

Hackers hit Kelp DAO on April 18, 2026.
They exploited a flaw in its LayerZero cross-chain bridge and minted counterfeit rsETH tokens.
This let them borrow over $236 million in assets and create ripples across platforms like Aave.

The industry is in deep trouble.
DeFi losses have topped $750 million by mid-April 2026, including a major $285 million hack at Drift.
The Kelp DAO exploit, combined with April's $606 million in losses, ranks as the worst month for crypto security since the Bybit breach.

Context: The Rising Tide of DeFi Exploits

DeFi drives blockchain innovation with decentralized lending, borrowing, and trading.
Cross-chain protocols like LayerZero enable asset transfers between blockchains, but they also bring big risks.
Attackers target these bridges because they create single points of failure.

Bridge exploits have caused most of the damage.
By mid-April 2026, DeFi protocols lost over $750 million, with April alone hitting $606 million.

"This single-validator architecture flaw allowed attackers to mint counterfeit rsETH, which was subsequently used to borrow over $236 million in assets."
, AInvest (AInvest)

Details: Unpacking the Kelp DAO Exploit

Attackers struck on April 18, 2026, by exploiting a flaw in LayerZero's single-validator setup.
They minted fake rsETH tokens and used them to drain $292 million through borrowing on integrated platforms.
This created over $236 million in bad debt on Aave and showed how risks connect in DeFi.

LayerZero claims the problem came from Kelp DAO's security setup, not a protocol bug.
They say no evidence points to wider contagion, but trust in bridges is shaky.

The hack was fast and huge, making it a key event for DeFi in 2026.
Reports suggest sophisticated groups might be involved, possibly North Korea's Lazarus, though that's unconfirmed.
LayerZero's ZRO token dropped 30 percent, reflecting market worries.

Reaction: Market Jitters and Community Response

The DeFi community is alarmed by the Kelp DAO exploit.
LayerZero's ZRO token fell 30 percent, signaling fears about cross-chain safety.
Forums buzz with demands for better audits and multi-validator systems.

Many argue bridge providers must take more blame.
This debate will likely influence future DeFi security rules.

Kelp DAO and platforms like Aave are fixing the mess and restoring liquidity.
The broader sector stands at a turning point where regulators might intervene if protocols don't step up.
Watch for updates from LayerZero and Kelp DAO as they race to avoid another disaster.