A major exploit targeting KelpDAO and LayerZero rippled through DeFi markets over the weekend. According to Arkham Intelligence, the attacker drained over $228 million from AAVE and Compound. LayerZero identified the attacker as the Lazarus Group, which manipulated bridge messaging to release 116,500 rsETH from KelpDAO's Ethereum bridge contract.
Fake Messages Bypass Verification
Arkham Intelligence's tracking shows the attacker submitted a fraudulent transfer record to LayerZero's verification system. This tricked the bridge contract into releasing 116,500 rsETH, inflating circulating supply on Ethereum. However, separate research by banteg indicates the attacker drained existing cross-chain inventory rather than minting new tokens — before the exploit, total rsETH supply was 629,689, with 151,967 rsETH distributed across chains like Arbitrum, Mantle, and Base.
Liquidity Crunch Hits AAVE Pools
The attacker used rsETH as collateral on AAVE, borrowing over $200 million in ETH — a large chunk of rsETH liquidity. That move immediately strained lending pools. As panic withdrawals surged, stablecoin supply caps hit limits, draining liquidity from USDC and USDT markets. Data shows about 87.9% of rsETH supply sits inside AAVE and Compound. On Ethereum, AAVE holds over 525,000 rsETH, while Arbitrum, Mantle, and Base each show over 90% concentration within AAVE.
rsETH Depegs to 82% as Recovery Options Emerge
On Ethereum, rsETH dropped to roughly 82% of its original value, reflecting market shock from the supply spike and uncertainty. KelpDAO now faces tough choices: one plan spreads losses across all holders, valuing rsETH near 84% of peg; another prioritizes Ethereum mainnet holders with full backing while limiting recovery for cross-chain users. About 40,374 rsETH has moved to an Ethereum multisig, possibly consolidating remaining assets. Arkham Intelligence warns that AAVE users may face rising borrow costs if liquidity remains tight.

