Kelp DAO says its restaked Ether token has been restored after a five-week recovery effort following a $293M exploit by North Korea's Lazarus Group on April 18
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance …
Context & Ripple Effects
Kelp DAO paused all rsETH contracts after the April bridge drain, while related coverage tied the incident to concerns about bad debt and reported substantial outflows from Aave. The restoration marks the end of an operational containment-and-recovery period rather than the end of the underlying security questions.
The episode sits within a broader run of alleged North Korea-linked crypto thefts: researchers attributed a large share of year-to-date hack losses to attacks including KelpDAO and Drift Protocol. Earlier recovery efforts in DeFi also show that restoring stolen assets can depend on intervention in contracts, not solely on decentralized market processes.
First-order effects
- Kelp DAO can resume normal use of rsETH after five weeks of paused contracts, removing the immediate freeze imposed after the bridge exploit.
- rsETH holders and protocols exposed to the token regain a functioning asset, but Kelp DAO must demonstrate that the restored system addresses the bridge failure that led to the pause.
Second-order effects
- Lending and liquidity venues that reacted to the exploit, including amid Aave bad-debt concerns, can reassess rsETH-related risk settings as the token returns to operation.
- Other restaking and cross-chain token issuers face pressure to review bridge controls, emergency-pause processes, and recovery mechanisms, since an exploit can quickly transmit risk into connected DeFi markets.
Third-order effects
- If large bridge exploits continue to produce protocol pauses and market-wide risk reactions, composability will increasingly be conditioned on stronger security assurances and clearer incident-recovery procedures.
- The recovery reinforces a tension in DeFi: users value decentralized infrastructure, but severe incidents can make contract upgrades, coordinated intervention, and legal or operational recovery pathways central to preserving confidence.
The trend: This is one data point in crypto’s shift from treating bridge exploits as isolated protocol failures to treating them as interconnected systemic-risk events requiring rapid containment and credible recovery.