An attacker targeting Kelp DAO's LayerZero-powered cross-chain bridge, appears to have drained ~$292M worth of rsETH before Kelp paused all rsETH contracts
Quick Take — An attacker seemingly drained 116,500 rsETH from Kelp DAO's LayerZero-powered cross-chain bridge on Saturday …
Context & Ripple Effects
The apparent bridge drain was followed in related coverage by concerns about bad-debt exposure that drove reported Aave outflows, extending the incident beyond Kelp DAO’s own token contracts.
Later disclosures tied the exploit to a deficient single-verifier setup, while Kelp said rsETH was restored after a five-week recovery. That sequence makes the incident a test of both cross-chain security design and recovery communications.
First-order effects
- Kelp DAO’s pause of all rsETH contracts immediately restricts normal activity around the affected restaked Ether token while the protocol contains and investigates the loss.
- LayerZero faces immediate scrutiny over the bridge configuration used by Kelp, particularly after its later acknowledgement that the single-verifier setup was deficient.
Second-order effects
- Users and lenders connected to rsETH can reassess collateral and counterparty risk; related coverage already links the exploit to major Aave outflows over bad-debt concerns.
- Other LayerZero applications using the same default verification arrangement face pressure to review or replace it; related reporting said roughly 47% of LayerZero OApps used that setup in April.
Third-order effects
- If cross-chain applications continue to rely on concentrated verification paths, bridge risk will be priced less as an isolated protocol failure and more as shared infrastructure exposure across DeFi.
- The episode raises the value of verifiable security assumptions and clear incident-response processes: recovery may restore an asset, but it does not automatically restore confidence in the surrounding bridge stack.
The trend: Cross-chain infrastructure is moving toward greater scrutiny of verification architecture as exploits expose how a single weak configuration can transmit risk across connected DeFi markets.