KelpDAO Exploit Signals New Era of Cross-Chain Cybercrime: Certik Analyst Warns Aave Becomes Debt Dumping Ground

KelpDAO Exploit Signals New Era of Cross-Chain Cybercrime: Certik Analyst Warns Aave Becomes Debt Dumping Ground

N
News Editor 01
2026-07-08 20:50:12
Certik blockchain analyst Wenzhao Dong reveals that the KelpDAO attack marks a shift where bridge vulnerabilities systematically infect lending markets. Arbitrum Security Council froze 30,766 ETH, but $220M remains missing. Attackers laundered 75,701 ETH to Bitcoin via mixers.
KelpDAOAavecross-chain securityLazarus GroupCertik

The KelpDAO exploit, which resulted in the theft of over $290 million in digital assets, has exposed a dangerous evolution in cross-chain cybercrime, according to Certik blockchain analyst Wenzhao Dong. Instead of simply draining tokens from a bridge, attackers leveraged the stolen funds to contaminate the broader DeFi ecosystem, turning a protocol vulnerability into systemic credit risk for lending platforms like Aave.

Arbitrum Security Council Freezes 30,766 ETH, but $220M Vanishes

On April 18, the Arbitrum Security Council (ASC) and SEAL 911 acted swiftly to freeze 30,766 ETH (approximately $71 million) on the Arbitrum network, preventing the attackers from moving these funds out. KelpDAO expressed gratitude for the “decisive action,” attributing the success to SEAL 911’s information coordination. However, authorities estimate that approximately $220 million worth of stolen assets remain unaccounted for. KelpDAO confirmed it is now working with Aave and other partners to address the “bad debt” generated by the attack and to restore rsETH parity.

Sophisticated Attack Vector: Bridge Vulnerability + Lending Protocol as Shield

In a post-mortem analysis, Wenzhao Dong detailed how the attackers — believed to be the North Korean Lazarus Group — demonstrated advanced knowledge of market liquidity. Rather than dumping the fraudulently minted rsETH directly on spot exchanges, they deposited the tokens as collateral on Aave and borrowed WETH. This novel approach effectively transferred the risk from the bridge exploit to the lending protocol, converting a one-time theft into persistent bad debt on Aave.

“The KelpDAO attack shows a clear risk pattern in modern DeFi,” Dong said. “A vulnerability in a bridge does not stay isolated — it becomes a problem for lending markets. By using fraudulently minted rsETH as collateral on Aave to borrow WETH, the attacker turned a bridge theft into Aave bad debt.” He contrasted this with the recent Hyperbridge incident, where hackers minted 1 billion Polkadot tokens but only managed to convert about $240,000 before the price collapsed. The KelpDAO attackers chose a far more efficient laundering route, avoiding slippage and early detection.

Security vs. Sovereignty: Community Divided Over Asset Freeze

The ASC’s emergency freeze has reignited a fundamental debate in blockchain circles: immutable decentralization versus pragmatic governance. Purists argue that the ASC’s ability to unilaterally freeze assets represents a “slippery slope” toward the centralized financial systems that crypto aims to replace. They fear that if a council can censor a hacker today, it might be pressured to censor political dissidents or legitimate businesses tomorrow. Pragmatists, on the other hand, view absolute decentralization as an aspirational end state, not a day-one requirement. They contend that DeFi needs “circuit breakers” to mitigate catastrophic losses from state-sponsored hackers. ASC stated it acted based on law enforcement intelligence and ensured no impact on regular Arbitrum users or applications.

Funds in Motion: 75,701 ETH Moved to Bitcoin via Mixers

In a worrying development, the KelpDAO attacker transferred 75,701 ETH (approximately $175 million) to the Ethereum mainnet and began funneling the stolen funds toward Bitcoin using various mixers. This cross-chain laundering strategy underscores the growing complexity of tracking and recovering stolen crypto assets. The move also highlights how attackers exploit the very interoperability that DeFi champions.

Wenzhao Dong concluded: “DeFi security is interconnected. Protocols cannot focus solely on their own contracts; they must account for risks from all system dependencies and implement defensive measures accordingly.” The KelpDAO incident serves as a stark reminder that cross-chain composability, while powerful, introduces systemic risk vectors that demand holistic security frameworks.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.