Blockchain analyst Wenzhao Dong of Certik has published a post-mortem revealing that the KelpDAO exploit demonstrates a dangerous new phase in cross-chain cybercrime. Unlike previous incidents where attackers immediately dumped stolen tokens on spot markets, the North Korea-backed Lazarus Group strategically routed their activity through Aave, turning a bridge theft into systemic bad debt for the lending protocol.
Emergency Freeze and Community Debate
On April 18, the Arbitrum Security Council (ASC), supported by SEAL 911 and law enforcement, froze 30,766 ETH (approximately $71 million) linked to the KelpDAO exploiter. The intervention prevented the hackers from moving these funds off the Arbitrum network, marking a clear victory for victims. However, the action reignited a fundamental debate within the blockchain community: the tension between immutable decentralization and pragmatic governance. Critics argue that the ASC’s ability to unilaterally freeze assets sets a dangerous precedent—if a council can censor a hacker today, it could be coerced into censoring a political dissident or legitimate business tomorrow. Proponents counter that for DeFi to achieve mainstream adoption, it must have “circuit breakers” to mitigate catastrophic losses, positioning the ASC as a necessary “digital fire department.”
Attack Analysis: From Bridge Vulnerability to Lending Bad Debt
Dong noted that the attackers deliberately avoided spot markets, where massive sell orders would have triggered slippage and early detection. Instead, they used falsely minted rsETH as collateral on Aave to borrow WETH, effectively shifting the risk onto the lending protocol. “A bridge vulnerability doesn’t stay isolated; it turns into a problem for lending markets,” Dong explained. This approach stands in stark contrast to the recent Hyperbridge incident, where attackers minted 1 billion Polkadot but only managed to convert about $240,000 before the price crashed. The KelpDAO hackers displayed a sophisticated understanding of market liquidity and executed a far more efficient “cash-out” route.
Ongoing Recovery and Risks
Despite the successful freeze, approximately $220 million in digital assets remain missing. KelpDAO confirmed that its primary focus is now working with Aave and other partners to address the “bad debt” created by the exploit, while also pursuing all available avenues to support rsETH holders and restore the protocol’s peg. Hours after the freeze, the attacker moved all 75,701 ETH to the Ethereum mainnet and began routing $175 million to Bitcoin, further complicating recovery efforts. This case underscores the interconnected nature of DeFi security: protocols cannot focus solely on their own contracts; they must consider the risks posed by every dependency in their system and implement defensive measures accordingly.

