The decentralized finance sector is scrambling to contain the fallout from the largest crypto exploit of 2026: a $292 million breach of KelpDAO's LayerZero-powered cross-chain bridge, which security researchers have linked to North Korea's Lazarus Group—the state-sponsored hacking unit responsible for billions in prior crypto thefts.
The attacker drained 116,500 rsETH—approximately 18% of the token's circulating supply—by compromising two RPC nodes that fed transaction data to the LayerZero relayer. A simultaneous DDoS attack forced the bridge into failover mode, opening a narrow window in which the verifier signed off on a fabricated cross-chain message.
Aave Leads Emergency Coalition
Aave, the largest DeFi lending protocol with roughly $18 billion in total value locked, immediately froze rsETH markets and has assembled an emergency coalition including Lido Finance, EtherFi, and Aave founder Stani Kulechov to coordinate a recovery plan. The coalition is proposing to pool ether from multiple protocols to cover the shortfall, to be repaid through KelpDAO's insurance fund over 12–18 months.
DeFi's aggregate TVL shed approximately $13 billion in the 48 hours following the exploit as users withdrew funds in fear of contagion. SparkLend and Fluid also froze rsETH markets, while Circle temporarily suspended USDC bridging involving the compromised chains.
Single-DVN Architecture at Fault
Security auditors point to a fundamental design flaw: KelpDAO's bridge relied on a single decentralized verifier network, violating the industry best practice of using multiple DVNs. The exploit demonstrates once again that cross-chain bridges remain one of crypto's most dangerous attack surfaces.