A cross-chain bridge holding 116,500 rsETH (restaked ether) worth roughly $292 million was drained from Kelp DAO over the weekend, representing about 18% of the token's circulating supply. The attacker exploited LayerZero's cross-chain messaging layer at 17:35 UTC by forging a transfer instruction that appeared valid, tricking the bridge into releasing the funds. Kelp's emergency pauser multisig froze core contracts 46 minutes later (18:21 UTC), but two subsequent attempts at 18:26 and 18:28 UTC, each carrying another 40,000 rsETH drain attempt ($100 million), both reverted.
Attack Vector and North Korean Link
The exploit did not involve breaking encryption or compromising private keys. Instead, attackers manipulated data inputs fed into the system. Security experts link the attack to North Korean hacker groups, noting it follows the same playbook used against crypto trading firm Drift just three weeks earlier. Alexander Urbelis, CISO of ENS Labs, said: "This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule." Combined, the Drift and Kelp exploits have drained over $500 million in two weeks. Rather than dumping the stolen rsETH on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed roughly $190 million in ETH and related assets across Ethereum and Arbitrum.
Aave's Bad Debt Dilemma
Aave acted swiftly — freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing. However, the bad debt outcome hinges on how Kelp handles the shortfall. If losses are spread across all rsETH holders, the token faces an estimated 15% depegging, leading to roughly $124 million in bad debt for Aave. If losses are isolated to Layer 2 networks like Arbitrum and Mantle, bad debt could surge to $230 million.
Coinbase Quantum Risk Report
A 50-page report commissioned by Coinbase warns that while quantum computers cannot currently break crypto, the industry cannot wait. Authored by experts including Stanford's Dan Boneh, Ethereum Foundation's Justin Drake, and Eigen Labs' Sreeram Kannan, the report notes Google researchers' estimates that a sufficiently advanced quantum computer could one day crack Bitcoin's cryptography. The Ethereum Foundation has proposed quantum-safe digital signatures, and Solana is testing quantum-resistant wallets. Current quantum machines remain far from breaking standard encryption, but the engineering challenge is shrinking.

