KelpDAO Attack Results in Approximately ¥44 Billion Unauthorized Drain of rsETH, Caused by DeFi Bridge Vulnerability
⚡ What Happened
Ethereum restaking protocol KelpDAO was exploited through a bridge vulnerability, resulting in the unauthorized drain of an estimated ¥44 billion worth of rsETH. There is a risk of ripple effects across the entire DeFi ecosystem's collateral structure, raising concerns about the impact on lending protocols such as Aave that accept rsETH as collateral. Going forward, the focus will be on whether on-chain tracking can enable fund freezing and on strengthening security audits for similar protocols.
This is one of the largest hacks in DeFi history at approximately ¥44 billion. Bridge vulnerabilities represent a structural weakness following Ronin (approximately ¥80 billion) and Wormhole (approximately ¥40 billion), and the complexity of cross-chain restaking amplified the risk. Restaking, led by EigenLayer, grew rapidly in 2024–25, but this is a textbook example of "composability risk," where each additional layer expands the smart contract attack surface. Because major DeFi protocols like Aave had accepted rsETH as collateral, the impact of the attack cascaded beyond KelpDAO alone. This deals a blow to overall DeFi TVL and credibility, potentially dampening institutional investors' appetite for DeFi participation. For regulators, it provides a compelling argument for tighter DeFi regulation.
🔍 The fundamental issue is that restaking's "yield stacking model" grew faster than its security verification could keep pace. KelpDAO's bridge had reportedly undergone external audits, but the scope and depth of those audits failed to cover the compounded inter-protocol risks. Furthermore, the structure in which derivative tokens like rsETH circulate as collateral throughout DeFi creates a "DeFi domino effect" where a single point of failure cascades across the entire system. The attacker likely understood this interdependent structure and chose the point of maximum impact.
📰 Source: CoinPost
🧭 Why This Is Moving Now
entities=ethereum / domain=crypto
🔮 Next Scenarios
🎯 Incentive Map
| Player | True Incentive | Deep Vulnerability | Predicted Action |
|---|---|---|---|
| KelpDAO Operations Team | Protocol survival and brand recovery. Minimizing legal liability | Obsession with rapid growth deprioritized security investment. VC funding pressure drove a speed-first approach | Negotiate with the attacker by offering a bug bounty while announcing a comprehensive security audit overhaul. Draft a victim compensation plan, though full reimbursement will be difficult |
| DeFi Lending Protocols (Aave, etc.) | Maintaining protocol health and protecting depositors. Immediately cutting rsETH collateral risk | Collateral diversification and yield chasing loosened risk management. Slow governance voting processes hinder emergency response | Freeze rsETH-related markets and raise liquidation parameters. Tighten acceptance criteria for restaking tokens going forward |
| Attacker | Cashing out funds and maintaining anonymity. Securing legitimate profit through bounty negotiations if possible | Moving large amounts of stolen funds on-chain is easily tracked, limiting exit strategies | Attempt to launder funds through mixers and cross-chain bridges, but partial return through negotiation remains a possibility |
⚠️ Pre-Mortem — Conditions Under Which This Prediction Fails
- The attacker agrees to negotiate and returns the majority of the funds as a bug bounty (precedent exists with Euler Finance, etc.)
- International law enforcement cooperation proceeds faster than expected and the attacker's wallets are frozen early
- The bias that "large-scale hacks are unrecoverable" may be causing us to underestimate actual recovery efforts and technological advances
Hit Condition: HIT if KelpDAO fails to recover more than 30% of the drained funds by June 30, 2026
Resolution Date: 2026-06-30