The fallout from the KelpDAO exploit is continuing to reverberate across decentralized finance, with Cardano founder Charles Hoskinson arguing that the incident exposed a structural weakness in cross-chain design rather than a conventional smart contract bug. The April 18 attack drained 116,500 restaked ETH, estimated at roughly $292 million, and was followed by a rapid wave of withdrawals across DeFi markets that reportedly exceeded $13 billion in total value locked within 48 hours.
In comments published after the incident, Hoskinson described the event as one of the year’s most significant DeFi exploits and framed it as evidence that bridge verification failures are becoming a more serious threat vector than traditional contract-level flaws. His broader argument is that DeFi’s risk model has changed: a single compromise in message verification can now cascade into lending markets, liquidity pools, and broader confidence across the ecosystem.
How the attack unfolded
According to the source material, the attacker used a spoofed Layerzero message that reached an endpoint v2 contract linked to Kelp’s restake adapter. That forged message triggered the release of assets from an Ethereum escrow. The fraudulent packet reportedly claimed Uni-Chain endpoint ID 30320 as its origin, while Kelp’s cross-chain configuration relied on a one-of-one decentralized verifier network. In practical terms, that meant a single verification path became a single point of failure.
Hoskinson said this setup illustrates why bridges can be especially dangerous when verification is too concentrated. Rather than dumping the stolen assets directly onto decentralized exchanges—which likely would have collapsed market pricing and made the attacker’s path noisier—the stolen restaked ETH was allegedly deposited into lending markets such as Aave. There, the assets were used as collateral to borrow more liquid wrapped ether, allowing the attacker to leave with assets disconnected from the original theft while the contaminated collateral stayed inside the system.
This mechanism is central to why the breach became more than a bridge incident. Instead of ending with a token drain, the exploit propagated into lending infrastructure and created what Hoskinson characterized as a contagion event. In his view, the issue was not just the initial compromise, but the way DeFi composability amplified the damage once bad collateral entered major markets.
Contagion spreads through lending protocols
A joint incident report from Llamarisk published on April 20 said that 83,471 ETH equivalent was spread across seven attacker-linked wallets on Ethereum core and Arbitrum. The report laid out two possible resolution paths. One scenario socializes a 15.12% haircut across all restaked ETH holders, implying around $123 million in bad debt absorbed by Ethereum core’s reserve. The other isolates losses at the layer-two level, repricing affected tokens to 26.46% backing and generating approximately $230 million in bad debt concentrated across Mantle, Arbitrum, and Base, while leaving Ethereum core untouched.
The stress on lending markets was immediate. Aave alone reportedly experienced between $6.6 billion and $8.45 billion in outflows. Wrapped ETH pools on Arbitrum, Base, Mantle, Linia, and Plasma reached near-100% utilization, effectively freezing withdrawals in practice. At least nine DeFi protocols were identified as directly affected, including Compound, Morpho, Lido, Ethena, Pendle, Euler, Beefy, and Lombard Finance, in addition to Aave.
The larger takeaway from the incident is the speed with which confidence can disappear. Hoskinson pointed to the mismatch between the size of the original exploit and the magnitude of the subsequent reaction: a roughly $290 million theft triggering more than $13 billion in TVL flight in just two days. For him, that is less a simple hack headline and more a crisis of confidence in the plumbing that connects chains, staking wrappers, and lending venues.
Disagreement over accountability
Post-mortem reports have been published by KelpDAO, Layerzero, and Llamarisk, but the source material notes that the three accounts do not align on where responsibility ultimately lies. Layerzero announced on April 20 that it would no longer sign or attest messages for applications running a one-of-one DVN configuration, effectively pushing developers toward multi-verifier setups across the protocol.
Kelp, however, has argued that Layerzero’s default configuration shipped with single-source verification across multiple networks, including Ethereum, BNB Chain, Polygon, Arbitrum, and Optimism. It also claimed that roughly 40% to 50% of all Layerzero OFT applications may still be using the same one-of-one model. If accurate, that suggests the KelpDAO exploit may reflect a broader design risk rather than an isolated implementation mistake.
Onchain forensic clues reportedly point to possible links with the Lazarus Group, the North Korea-linked hacking collective often associated with major crypto thefts. Still, the article notes that no independent forensic firm has issued a formal attribution, and the FBI has not publicly commented. As a result, any direct attribution remains unconfirmed.
Why Hoskinson points to Cardano and Midnight
Hoskinson used the incident to contrast Cardano’s architecture with the restaking-heavy structures that have become common in parts of the Ethereum ecosystem. He argued that Cardano’s liquid, non-custodial staking model reduces the need for the layered stack of staking, liquid staking, and restaking wrappers that can create additional attack surfaces. In his framing, lower compositional complexity can translate into lower systemic risk.
He also highlighted Midnight, Cardano’s privacy-focused sidechain, as a possible answer to the kind of verification failure seen in the KelpDAO exploit. According to Hoskinson, Midnight’s Nightstream protocol can fold entire chain states into proofs that travel with cross-chain messages, allowing recipients to verify the validity of those messages before accepting them. His argument is that zero-knowledge proofs at the verification layer could block poisoned or forged messages before they trigger value release on the destination chain.
Beyond zero-knowledge proofs, Hoskinson said Midnight’s support for multi-party computation could make it easier to deploy more resilient verifier configurations such as two-of-three or five-of-seven DVN setups. The implication is that stronger threshold verification could reduce the operational friction that often leads projects to adopt weaker default settings.
Whether Cardano or Midnight will become meaningful infrastructure solutions for multi-chain DeFi remains an open question. But Hoskinson’s intervention is notable because it reframes the discussion from isolated bugs to systemic message integrity. In that sense, he is not only criticizing a specific bridge setup, but also making a broader case that cryptographic assurances and distributed verification need to be built deeper into cross-chain communication.
A warning for the next phase of DeFi security
Hoskinson also warned that the threat environment is worsening as attackers gain access to increasingly sophisticated AI tools. He suggested that advanced models can help malicious actors scan large codebases and discover emerging vulnerabilities that may not be obvious to any single human reviewer. In his assessment, hacks are becoming both more scalable and more difficult to defend against using old assumptions.
The KelpDAO exploit therefore stands as a case study in how modern DeFi failures can move across layers: from bridge verification to escrow release, from collateralization to bad debt, and from protocol-level losses to ecosystem-wide withdrawals. Even if the industry converges on stronger multi-verifier standards after this event, the incident highlights a deeper challenge: security is no longer just about whether a contract compiles safely, but whether interconnected systems can contain failure once trust at a bridge boundary breaks down.
For DeFi builders, the immediate lesson is that message verification design deserves the same scrutiny once reserved for contract audits. For users, the more sobering lesson is that composability can magnify risk as efficiently as it magnifies capital efficiency. And for competing ecosystems like Cardano, the episode provides an opportunity to argue that alternative architecture choices—especially around staking design and cross-chain verification—may become more relevant as the market reassesses what secure interoperability should look like.

