Kelp DAO Publishes Recovery Progress from Hack — Approximately 89,500 ETH Still Unrecovered
⚡ What Happened
On April 24, Kelp DAO published a progress report on loss recovery from the rsETH unauthorized drainage incident, reporting that approximately 73,700 ETH (about 45%) of the initial 163,200 ETH shortfall had been recovered. As a recovery process from a large-scale hack, the focus is now on recovering the remaining approximately 89,500 ETH, raising questions about the protocol's reliability and risk management across the entire DeFi ecosystem. Going forward, the results of discussions with various DeFi companies and progress on additional recovery will be key points of market attention.
This is a follow-up report on the large-scale hack incident involving Kelp DAO's rsETH. Kelp DAO's success in recovering approximately 45% of the funds represents a reasonable achievement when compared to major hack cases such as the 2022 Ronin Bridge (over $600 million) and Wormhole ($320 million) in terms of recovery rate. However, recovering the remaining approximately 89,500 ETH will not be easy. As interoperability among DeFi protocols increases, hack incidents have repeatedly materialized as a structural risk for the entire industry. The continuation of recovery negotiations suggests progress in negotiations with the hacker and on-chain tracking, but past cases rarely resulted in full recovery, with partial recovery being the more common outcome. The impact on rsETH holders and the ripple effects on trust across the entire LST protocol sector will be the focus going forward.
🔍 The timing of the progress "announcement" itself is strategic. The 45% recovery figure provides reassurance to the market that this is "not a total loss," while the intent to distribute responsibility for the remaining 55% recovery to "discussions with various DeFi companies" is apparent. The means by which the recovered 73,700 ETH was retrieved is not clear from the published information, but multiple methods are conceivable, including negotiations with the hacker, bug bounty-style deals, and on-chain tracking. The recovery of the remainder may have entered a phase that is even more difficult technically and legally. The expression "in discussions with various DeFi companies" suggests that behind-the-scenes negotiations are underway to have related protocols share a portion of the losses, and the power dynamics within the industry are being tested.
📰 Source: CoinPost
🧭 Why This Is Moving Now
entities=ethereum / domain=crypto
🔮 Next Scenarios
🎯 Incentive Map
| Player | True Incentive | Underlying Vulnerability | Predicted Behavior |
|---|---|---|---|
| Kelp DAO Operations Team | Protocol survival and team reputation preservation. Constructing a narrative of "having done their best" takes priority over full reimbursement | Fear of accountability and sunk cost bias driven by the desire to continue the project | Regularly publish recovery progress to demonstrate transparency while avoiding promises of full reimbursement, seeking settlement through partial recovery |
| DeFi Partner Protocols | Minimizing their own losses. Cooperation with Kelp DAO is for maintaining industry trust, but they want to avoid outflow of their own funds | Concern about reputational risk for the entire industry and wariness about setting a precedent | Show a cooperative stance publicly while keeping actual contributions to a minimum, limiting involvement to technical assistance and small donations |
| Hacker (Attacker) | Retaining the maximum amount of stolen funds. Partial return is possible depending on the balance with legal risk, but as long as anonymity is maintained, the inclination is to keep everything | Difficulty liquidating funds (large ETH movements are tracked) and anxiety over international law enforcement cooperation | Continue gradual money laundering through mixers and cross-chain bridges. If pressure mounts, may return a portion to bring things to a close |
⚠️ Pre-Mortem — Conditions Under Which This Prediction Fails
- A case where the hacker responds to legal pressure or a bounty proposal and voluntarily returns the majority of the funds. There is precedent for full return in cases such as Euler Finance, and resolution could come sooner than expected.
- A case where a major protocol or insurance fund emerges from discussions with DeFi companies to absorb the losses, and reimbursement is achieved through stablecoins or tokens rather than ETH. A flexible solution that does not insist on ETH-denominated recovery may have been overlooked.
- The prediction may be overly reliant on the narrative that "large-scale hacks are difficult to recover from," influenced by past successful recovery cases. Advances in on-chain analysis technology have rapidly improved tracking and freezing capabilities.
Fear-Setting / When this prediction fails
- This probability fails if the hacker voluntarily returns over 50% of remaining funds in response to a bounty offer or legal pressure, as seen in the Euler Finance precedent.
- This probability fails if a major DeFi insurance protocol or partner fund steps in to cover the shortfall through token-based compensation rather than ETH recovery.
- This probability fails if law enforcement agencies successfully identify and arrest the hacker, forcing asset seizure and return within the deadline.
Hit Condition: HIT if Kelp DAO fails to recover an additional 44,750 ETH or more by June 30, 2026
Resolution Date: 2026-06-30