Certik Warns KelpDAO Cross-Chain Attack Exposes Systemic DeFi Bad Debt Risk

Certik Warns KelpDAO Cross-Chain Attack Exposes Systemic DeFi Bad Debt Risk

N
News Editor 01
2026-07-08 18:34:12
Certik analyst Wenzhao Dong warns that the KelpDAO exploit marks a shift where bridge vulnerabilities are weaponized to infect lending markets. Arbitrum Security Council froze 30,766 ETH, but $220 million remains missing.
KelpDAOcross-chain attackDeFi bad debtAaveLazarus Group

Blockchain analyst Wenzhao Dong of Certik has published a post-mortem revealing that the KelpDAO exploit demonstrates a dangerous new phase in cross-chain cybercrime. Unlike previous incidents where attackers immediately dumped stolen tokens on spot markets, the North Korea-backed Lazarus Group strategically routed their activity through Aave, turning a bridge theft into systemic bad debt for the lending protocol.

Emergency Freeze and Community Debate

On April 18, the Arbitrum Security Council (ASC), supported by SEAL 911 and law enforcement, froze 30,766 ETH (approximately $71 million) linked to the KelpDAO exploiter. The intervention prevented the hackers from moving these funds off the Arbitrum network, marking a clear victory for victims. However, the action reignited a fundamental debate within the blockchain community: the tension between immutable decentralization and pragmatic governance. Critics argue that the ASC’s ability to unilaterally freeze assets sets a dangerous precedent—if a council can censor a hacker today, it could be coerced into censoring a political dissident or legitimate business tomorrow. Proponents counter that for DeFi to achieve mainstream adoption, it must have “circuit breakers” to mitigate catastrophic losses, positioning the ASC as a necessary “digital fire department.”

Attack Analysis: From Bridge Vulnerability to Lending Bad Debt

Dong noted that the attackers deliberately avoided spot markets, where massive sell orders would have triggered slippage and early detection. Instead, they used falsely minted rsETH as collateral on Aave to borrow WETH, effectively shifting the risk onto the lending protocol. “A bridge vulnerability doesn’t stay isolated; it turns into a problem for lending markets,” Dong explained. This approach stands in stark contrast to the recent Hyperbridge incident, where attackers minted 1 billion Polkadot but only managed to convert about $240,000 before the price crashed. The KelpDAO hackers displayed a sophisticated understanding of market liquidity and executed a far more efficient “cash-out” route.

Ongoing Recovery and Risks

Despite the successful freeze, approximately $220 million in digital assets remain missing. KelpDAO confirmed that its primary focus is now working with Aave and other partners to address the “bad debt” created by the exploit, while also pursuing all available avenues to support rsETH holders and restore the protocol’s peg. Hours after the freeze, the attacker moved all 75,701 ETH to the Ethereum mainnet and began routing $175 million to Bitcoin, further complicating recovery efforts. This case underscores the interconnected nature of DeFi security: protocols cannot focus solely on their own contracts; they must consider the risks posed by every dependency in their system and implement defensive measures accordingly.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.