DeFi protocol Kelp DAO suffered a major security breach on April 18, 2026, losing 116,500 rsETH tokens worth approximately $292 million. Attackers seized control of RPC nodes within LayerZero's decentralized verification network (DVN), launched a denial-of-service attack, and submitted a fraudulent cross-chain message that the system mistakenly validated.
Single-verifier design under fire
LayerZero's technical report identified Kelp DAO's use of a 1/1 single-verifier DVN configuration as the root cause. The setup eliminated independent oversight, creating a single point of failure. LayerZero claims it repeatedly warned Kelp DAO about DVN diversification best practices, yet the team continued operating with the risky configuration. Kelp DAO countered that the single-verifier option was listed as a default in LayerZero's own documentation and was approved through direct communication with LayerZero's team.
Kelp DAO said it had been running on LayerZero infrastructure since January and maintained ongoing coordination. After the attack, the team blacklisted attacker wallets and paused relevant smart contracts — quick actions that helped contain the situation.
Ripple effects: Aave V3 at risk
The attacker deposited most stolen rsETH into Aave V3 as collateral, borrowing 82,650 WETH and 821 wstETH against it. This created potential bad debt for Aave. According to Aave's analysis, the attacker used 89,567 rsETH (~$221M) as collateral. Two scenarios are under consideration due to Kelp DAO's unclear loss-sharing plan.
Scenario one: proportional loss distribution across all networks would cut rsETH supply value by 15.12%, generating ~$123.7M in bad debt on Aave, with Ethereum mainnet bearing $91.8M. Scenario two: if only L2 rsETH is affected, L2 assets face a 73.54% haircut, creating $230.1M in bad debt. Aave's $54M "WETH Umbrella" insurance fund only applies in scenario one. Aave currently holds $181M in assets and has secured community commitments for additional support.

