GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

DeFi United Raises Over $300 Million in Funding

Circle Ventures, Consensys, and Joseph Lubin have announced their support for the DeFi United initiative, aimed at mitigating losses caused by the Kelp DAO vulnerability. Circle Ventures is supporting the ecosystem by purchasing AAVE tokens. Consensys and Ethereum co-founder Joseph Lubin have confirmed the provision of 30,000 ETH to DeFi United. To date, DeFi United has raised over 132,000 ETH, with a total value exceeding $300 million. These funds will be used to cover bad debts resulting from an attacker minting unbacked rsETH via the LayerZero bridge and borrowing assets on Aave. Previously, Aave proposed a donation of 25,000 ETH, while Lido DAO, Ether.fi, and Kelp have respectively proposed or pledged donations of 2,500 ETH, 5,000 ETH, and 2,000 ETH.

An address deposited 1.397 million UNI tokens—worth approximately $4.6 million—to three exchanges two hours ago.

According to on-chain analyst Ai Aunt (@ai_9684xtpa), the address 0xb5E…Fc24e deposited a total of 1.397 million UNI tokens—worth approximately $4.6 million—into three exchanges two hours ago. Notably, the Bybit deposit address has had multiple interactions with the DeFi crypto fund DeFiance Capital, which is an investor in both Aave and LayerZero—two entities closely linked to the recent Kelp DAO hack incident.

JPMorgan: Frequent DeFi hacks and stagnant TVL continue to suppress institutional participation

According to The Block, JPMorgan analysts noted in their latest report that ongoing DeFi security vulnerabilities and stagnant growth in total value locked (TVL) continue to constrain institutional enthusiasm for the DeFi sector. Recently, Kelp DAO’s cross-chain bridge suffered a major attack, during which the attacker minted $292 million worth of uncollateralized rsETH tokens and borrowed real ETH on Aave, resulting in approximately $230 million in bad debt. This caused DeFi TVL to evaporate by roughly $20 billion within several days. LayerZero and blockchain security researchers have attributed this attack to the North Korean hacker group Lazarus Group; some of the stolen funds have been frozen, while the rest remain in circulation. Analysts also pointed out that DeFi TVL denominated in ETH has remained range-bound for an extended period, raising market concerns about whether DeFi can achieve organic growth sufficient to support institutional adoption. Furthermore, following each security incident, users tend to shift funds into USDT as a safe-haven asset—yet this trend has not yet significantly driven USDT’s market capitalization growth.

rsETH Hack Causes 68,900 ETH Shortfall; DeFi United Raises 13,500 ETH for Industry自救

According to on-chain analyst Ember (@EmberCN), the rsETH incident on April 18 resulted in a funding shortfall of approximately 68,900 ETH (around $160 million): the hacker collateralized rsETH to borrow 99,600 ETH; after Arbitrum recovered 30,700 ETH, the remaining funds were fully converted by the hacker into BTC. The incident has now entered the remediation phase. Aave is coordinating the establishment of a “DeFi United” relief fund, which has so far received cumulative donations totaling 13,500 ETH (approximately $31.45 million). Donors include Lido Finance (2,500 stETH), ether.fi Foundation (5,000 ETH), Aave founder Stani Kulechov (5,000 ETH), Golem Foundation (1,000 ETH), as well as LayerZero and Ink Foundation (amounts undisclosed).

Lido proposes using up to $5.8M stETH to cover Kelp’s funding gap

the Lido team has initiated a proposal, planning to allocate up to 2,500 stETH (approximately $5.8 million) from the DAO to cover the rsETH asset shortfall resulting from the recent attack on Kelp DAO.Lido noted that the LayerZero-based exploit has led to insufficient rsETH reserves, triggering a chain reaction across the DeFi ecosystem, including rising interest rate pressure, tightening lending markets, and certain leveraged strategies facing passive liquidation risks.The proposal emphasizes that these funds will only be used as part of a complete recovery solution, provided that the overall shortfall can be fully addressed.Previously, the approximately $292 million attack on Kelp DAO had already impacted Aave, leading to bad debt issues, and its total value locked (TVL) once declined by nearly $8 billion.

The KelpDAO attacker bridged funds to Arbitrum and then transferred them to TRON.

According to on-chain analyst PeckShield (@PeckShieldAlert), the KelpDAO attacker has transferred ETH from Ethereum to Arbitrum via the Across Protocol, swapped it for USDT, and then routed the funds to TRON DAO via LayerZero.

Dune Releases Security Analysis of LayerZero OApp: 47% of Contracts Still Use the Minimal 1-of-1 DVN Configuration

According to an official Dune disclosure, following the KelpDAO hack, Dune conducted a security configuration analysis of LayerZero’s DVN (Decentralized Verification Network) for nearly 90 days of active OApps. The data shows that among approximately 2,665 distinct OApp contracts, 47% adopted the 1-of-1 DVN security threshold—the lowest level—45% adopted 2-of-2, and roughly 5% adopted 3-of-3 or higher configurations; KelpDAO’s rsETH resides at the 1-of-1 tier, the minimum security level.

Curve Founder Calls on DeFi Industry to Establish Unified Security Standards to Reduce Centralized Single Points of Failure

Michael Egorov (@newmichwill), founder of Curve Finance, posted that recent security incidents in the DeFi space—triggered by centralized failure points—have occurred frequently and severely damaged the industry’s reputation. Citing examples such as Aave users being unable to withdraw funds following the rsETH exploit and the LayerZero cross-chain bridge hack, he emphasized that problems must be prevented *before* they occur—not addressed only after damage is done. He called on the industry to jointly establish DeFi security standards, proposing that the Ethereum Foundation and Solana Foundation take the lead in collaborating with projects across ecosystems, auditing firms, and risk-assessment teams to develop principles and specifications for secure system design—and suggesting that lessons could be drawn from traditional finance’s approaches to safeguarding centralized nodes.

Aave Disclosure: Depending on the loss allocation method, potential bad debt amounts could be $123.7 million or $230.1 million.

Aave risk service provider LlamaRisk has released an incident report: On April 18, 2026, the attacker exploited a vulnerability in Kelp’s LayerZero V2 Unichain-to-Ethereum rsETH routing (a 1-of-1 DVN configuration flaw), forged inbound packets, and illicitly released 116,500 rsETH from the Ethereum-side adapter. Of these, 89,567 rsETH were deposited as collateral into multiple Aave V3 markets—including Ethereum Core and Arbitrum—enabling the borrowing of approximately 82,650 WETH (valued at ~$191 million) and 821 wstETH. Currently, only 40,373 rsETH remain in the adapter, while the total claimable rsETH on the remote chain stands at 152,577—creating a substantial shortfall. Depending on the loss allocation methodology, Aave faces two potential bad-debt scenarios: - Scenario 1 (global pro-rata allocation): Estimated bad debt of ~$123.7 million, with Ethereum Core bearing the greatest pressure; - Scenario 2 (loss confined to L2s): Estimated bad debt of ~$230.1 million, with Mantle facing a WETH reserve shortfall of up to 71.45% and Arbitrum facing a 26.67% shortfall. Following the incident, Aave Protocol Guardians and Risk Administrators immediately froze rsETH/wrsETH reserves across all 11 affected markets.

Kelp: The theft was due to LayerZero's RPC nodes being compromised; the 1/1 DVN configuration is LayerZero's default setting

Odaily News Kelp DAO officially posted on X regarding the follow-up on the theft incident, stating that the cause was the compromise of two RPC nodes hosted by LayerZero, while the third RPC node suffered a DDoS attack. This was an attack targeting LayerZero's infrastructure; Kelp's own systems were not involved in the construction or operation of this infrastructure.The 1/1 DVN configuration is the scheme documented in LayerZero's documentation and is the default setting for all new OFT deployments. Kelp has been operating on LayerZero's infrastructure since January 2024 and has maintained open communication with the LayerZero team. During Kelp's expansion to Layer2, the DVN configuration was discussed, and the default configuration was explicitly confirmed as appropriate at that time.Kelp's current top priority is to protect user interests and prevent risks from spreading within the DeFi ecosystem. The team is collaborating with various parties in the ecosystem to analyze the impact, seek support, and explore all possible mitigation solutions.

Lido: rsETH Theft Incident Affects EarnETH, Exposure Approximately $21.6 Million, Deposits and Withdrawals Suspended

Odaily News Lido posted on platform X stating that on April 18th, the Kelp cross-chain bridge was attacked, resulting in the theft of approximately 116,500 rsETH (worth about $292 million). Subsequently, the related assets were frozen on lending markets such as Aave.Its treasury product EarnETH has approximately a 9% risk exposure (about $21.6 million) through leveraged rsETH/ETH positions on Aave. Meanwhile, rising borrowing utilization is creating cost pressure on other strategies. The team is advancing deleveraging and reducing overall risk.Lido pointed out that the final impact of the rsETH positions depends on the subsequent handling by Kelp, LayerZero, and Aave, including loss sharing, asset recovery, and bad debt processing.Regarding risk mitigation, EarnETH can, if necessary, activate a $3 million "first-loss protection mechanism" (provided by the DAO treasury) to cover losses. The specific scale of its use is still pending further evaluation. Currently, the treasury has suspended deposits and withdrawals to ensure fairness and complete loss assessment. If the handling process is slow, redemption channels may be reopened based on the worst-case loss expectations.The official emphasized that stETH and wstETH are unaffected, and the core staking protocol was not involved in this incident.

Lido EarnETH has approximately $21.6 million exposure to rsETH and plans to activate a $3 million first-loss protection mechanism.

According to an official Lido tweet, on April 18, 2026, attackers stole 116,500 rsETH (approximately $292 million) from the Kelp cross-chain bridge. Lending platforms including Aave subsequently froze the rsETH market. Lido’s EarnETH treasury holds approximately 9% exposure to rsETH (roughly $21.6 million) via leveraged positions on Aave; deposits and withdrawals are currently suspended. The EarnETH team is actively reducing leverage and mitigating risk; the final loss amount will depend on subsequent decisions by Kelp, LayerZero, and Aave. The Lido DAO treasury has a $3 million “first-loss protection mechanism,” which may be activated—via burning DAO treasury shares—as needed. Lido’s core staking protocol, as well as stETH and wstETH, remain unaffected by this incident.

Kelp DAO Counters LayerZero’s Attribution of the $290M rsETH Vulnerability

According to CoinDesk, Kelp DAO will dispute LayerZero’s explanation of the $290 million rsETH cross-chain bridge vulnerability, stating that the compromised single-validator configuration relied on LayerZero’s own infrastructure and that this setup was part of LayerZero’s default integration—rather than a custom choice by Kelp DAO violating recommended practices. The attacker stole approximately 116,500 rsETH by compromising the servers LayerZero used to verify cross-chain transactions and disrupting its fallback nodes. Kelp DAO emphasized that the incident affected only the LayerZero-based bridging layer, leaving its core liquidity re-staking contracts unimpacted. LayerZero subsequently responded by announcing it would cease signing messages for any applications using a single-validator configuration and would mandate secure migration.

SlowMist’s Yu Xian dissects the KelpDAO hack: Targeted poisoning of RPC infrastructure; LayerZero’s DVN issued validation for forged transactions

According to an analysis by SlowMist founder Yu Xian (@evilcos), the core of the recent KelpDAO hack—resulting in approximately $290 million stolen—was a targeted poisoning attack against the downstream RPC infrastructure of LayerZero’s DVN (Decentralized Validator Network). The specific attack steps were as follows: First, the attackers obtained the list of RPC nodes used by LayerZero’s DVN; second, they compromised two independent RPC clusters and replaced their op-geth binary files; third, using selective spoofing techniques, they returned forged malicious payloads exclusively to the DVN while serving legitimate data to all other IPs; fourth, they launched DDoS attacks against uncompromised RPC nodes, forcing the DVN to fail over to the poisoned nodes; finally, after the forged messages were validated, the malicious binary self-destructed and erased its logs. As a result, LayerZero’s DVN signed validations for transactions that “never occurred.”

LayerZero: KelpDAO Loses $290 Million Due to Single DVN Configuration; Protocol Itself Has No Vulnerabilities

Currently, the LayerZero Labs DVN has resumed operations and announced that it will no longer sign or verify messages for applications still using the 1/1 configuration. LayerZero has collaborated with multiple law enforcement agencies worldwide and is actively assisting in tracking the stolen funds.

Kelp DAO Hacked, Triggering Aave Liquidity Crisis; Users Withdraw $6.2 Billion

Odaily News: A LayerZero cross-chain bridge related to Kelp DAO was hacked on Saturday, resulting in 116,500 rsETH worth $291 million flowing to a new wallet. The hacker used the illicitly obtained rsETH as collateral to borrow on Aave, causing the utilization rate of Aave's core lending pool to reach 100% and triggering a liquidity crunch. According to monitoring by 0xngmi, as of early Sunday, the net withdrawal amount from Aave had reached $6.2 billion. Kelp DAO has suspended the rsETH contracts on the Ethereum mainnet and several L2 networks. Affected by this, the price of the Aave token fell 16% to $90.13, and the price of Ethereum dropped 2% to $2,300. Currently, Justin Sun has posted on platform X attempting to negotiate with the hacker.

Curve Finance Suspends LayerZero Cross-Chain Bridging Functionality in Response to rsETH Infrastructure Hack

According to an official announcement from Curve Finance, due to a hacker attack on the rsETH LayerZero infrastructure, Curve Finance has suspended its LayerZero infrastructure for security reasons, pending further investigation into the root cause before resuming operations. This suspension affects the following: cross-chain bridging of CRV tokens from BNB Chain, Sonic, Avalanche, Fantom, Etherlink, and Kava (chains using native bridges remain unaffected), as well as the crvUSD fast bridge functionality (the L2 slow bridge remains fully operational). Meanwhile, KelpDAO is also reported to have suffered a vulnerability exploit involving approximately $291 million; the exact extent of losses is still under investigation.

Curve Finance Suspends LayerZero Infrastructure

According to an official announcement, Curve Finance has suspended its LayerZero infrastructure as a precautionary measure following a hacker attack on rsETH’s LayerZero infrastructure, pending further investigation into the root cause. This adjustment affects cross-chain CRV bridging initiated from chains including BNB, Sonic, Avalanche, Fantom, Etherlink, and Kava; bridging from other chains remains unaffected and continues to use native bridges. Additionally, the crvUSD fast bridge is impacted, while the slower bridge to L2s remains fully operational.

An address deposited 978,000 ZRO tokens to Binance, valued at approximately $1.57 million.

According to on-chain analyst Yujin (@EmberCN), ZRO—the native token of LayerZero, the cross-chain bridge exploited by hackers in today’s rsETH vulnerability incident—fell 18% on the day, dropping from $1.90 to $1.50. Twenty minutes ago, a Polymarket user with the address “greenrooibos” deposited 978,000 ZRO tokens to Binance, valued at approximately $1.57 million. These ZRO tokens were withdrawn from Binance two weeks ago, when they were worth roughly $2.04 million; this deposit thus corresponds to a loss of approximately $470,000.

Axelar Network Calls for Enhanced Multi-Layer Security for Cross-Chain Bridges

Axelar Network stated that the hacker attack and theft of funds undermine users’ overall trust in blockchain systems and slow down the adoption of the global ledger it envisions. Axelar expressed its support for the LayerZero team in navigating this difficult situation and rebuilding trust. Regarding this approximately $290 million attack, Axelar emphasized that—pending final forensic findings—the incident once again highlights the need for multi-layered security in cross-chain bridge construction. This includes ensuring operational security for bridge operators, validators, and validating nodes; providing proper incentives and training; and removing validators whose technical capabilities are not adequately demonstrated. Additionally, operators must be sufficiently numerous, structurally heterogeneous, diverse, and geographically distributed to prevent ultimate control by a single entity.