KelpDAO $290M Hack Exposes DeFi Security Flaws, Triggers Aave TVL Collapse
KelpDAO suffered a $290 million exploit in April 2026 due to a critical flaw in a LayerZero bridge, exposing DeFi security vulnerabilities. Aave's total
Summary
- KelpDAO suffered a $290 million exploit in April 2026 due to a critical flaw in a LayerZero bridge, exposing DeFi security vulnerabilities.
- Aave's total value locked (TVL) plummeted by $6-8.45 billion in days, reflecting widespread panic and liquidity outflows.
- The hack contributed to a $13 billion drop in overall DeFi TVL, raising urgent concerns about cross-chain bridge safety.
A staggering blow hit decentralized finance when KelpDAO lost $290 million in an exploit in April 2026.
The vulnerability in a LayerZero cross-chain bridge caused the loss.
LayerZero Labs confirmed a single point of failure in the 1-of-1 DVN setup.
This shook the ecosystem and triggered financial fallout across platforms.
DeFi has become a key part of the crypto economy.
It manages billions in user funds through lending, staking, and bridging protocols.
Cross-chain bridges like LayerZero are essential for moving assets between blockchains.
Their complexity makes them easy targets for attackers.
The KelpDAO incident shows how big the risks are.
The sector faces more scrutiny after losses like this one.
The KelpDAO hack exploited a flaw in the LayerZero bridge's DVN setup.
Attackers drained $290 million in assets.
KelpDAO paused contracts to stop a second theft of $95 million.
Aave took the hardest hit due to its ties to cross-chain systems.
Its TVL fell from $26.4 billion to between $17.947 billion and $20 billion.
This drop highlights the dangers of linked DeFi protocols.
The overall DeFi market lost $13 billion in TVL in two days.
"The KelpDAO exploit is a stark reminder of the systemic risks embedded in cross-chain bridges, which are often the weakest link in DeFi's infrastructure."
, Galaxy Research (Galaxy)
The market reacted fast to the KelpDAO hack.
Aave's TVL outflows showed a loss of trust in DeFi.
Users pulled funds to avoid more risks.
Online discussions highlight worries about bridge security.
The scale of Aave's drop has sparked calls for better practices.
Smaller platforms could be even more at risk.
KelpDAO paused contracts and worked with the Arbitrum Security Council.
This limited the damage from the exploit.
The industry must focus on prevention now.