Kelp DAO said the exploit happened at 17:35 UTC on Saturday, when an attacker used a targeted call to the "lzReceive" function in LayerZero’s EndpointV2 contract. That call led Kelp’s bridge logic to release about 116,500 rsETH, valued at roughly $292 million, to addresses controlled by the attacker.
The team’s investigation said the setup began well before the breach. Roughly 10 hours earlier, the attacker funded activity through Tornado Cash, adding a layer of anonymity before the exploit was carried out. Kelp DAO’s emergency team responded within one hour, triggering a full protocol pause that stopped the rsETH token, the LRT Deposit Pool, withdrawal modules, and oracle components.
Emergency pause blocked two more drain attempts
After the main exploit, the attacker tried to execute two more drains valued at about $50 million each. Both attempts failed because the protocol had already been suspended. Based on the figures disclosed by the project, total damage could have reached nearly $391 million without that intervention.
In a public statement, Kelp DAO said it had detected suspicious cross-chain activity involving rsETH and paused rsETH contracts across mainnet and several Layer 2 networks while the investigation continued. The project said it was working with LayerZero, Unichain, auditors, and external security experts on root cause analysis. Kelp DAO operates as a liquid restaking and cross-chain DeFi protocol across more than 20 blockchain networks, including Arbitrum, Base, and Scroll. Before the incident, about 630,000 rsETH were in circulation.
Aave freezes rsETH markets to limit bad debt exposure
The impact spread quickly across DeFi, with Aave moving to freeze all rsETH markets on Aave V3 and Aave V4. The action came as concerns grew that impaired rsETH liquidity could create bad debt pressure for lending markets. During the fallout, AAVE fell 10%. Aave said its own smart contracts were not exploited and that the issue was tied to the rsETH asset and the Kelp DAO bridge event.
Aave also said freezing the markets would stop new deposits and prevent borrowing against rsETH. The team added that any decision involving the platform’s Umbrella safety module would depend on whether actual losses emerge through secondary effects. The stolen amount equals about 18% of rsETH’s circulating supply, a figure that raises immediate concerns for holders and for protocols using the token as collateral.
Second major incident in twelve months
This is the second major security setback for Kelp DAO within 12 months. The source notes that in April 2025, a bug in its fee contract caused unintended rsETH minting and led to a temporary pause, though no user funds were lost in that episode.
rsETH was trading around $2,500 at the time referenced in the report, with volatility rising as uncertainty around the protocol deepened. Co-founder Amitej Gajjala and the core team had not issued detailed updates beyond the ongoing technical investigation. The project’s focus remained on working with LayerZero, Unichain, and outside security specialists while forensic review and recovery efforts continued.

