On April 18, an attacker exploited a cross-chain message forgery to drain 116,500 restaked ETH (worth approximately $292 million) from KelpDAO, prompting Cardano founder Charles Hoskinson to call it the largest DeFi exploit of the year. The breach triggered a contagion event that pulled more than $13 billion in total value locked (TVL) from the broader DeFi ecosystem within 48 hours, hitting major protocols including Aave, Compound, Morpho, and at least nine others.
Attack Details: Single-Verifier Configuration Was the Achilles' Heel
The attacker submitted a spoofed Layerzero message that reached the endpoint v2 contract connected to Kelp's restake adapter, which then released tokens from an Ethereum escrow. The forged packet claimed Uni-Chain endpoint ID 30320 as its source. Kelp's cross-chain configuration relied on a single decentralized verifier network (DVN), a one-of-one setup that gave the attacker a single point of compromise.
Rather than dumping the stolen tokens directly on decentralized exchanges—which would have crashed the price—the attacker deposited the restaked ETH as collateral in lending markets like Aave before Kelp or its partners could freeze positions. They then borrowed liquid wrapped ether against it and walked away with assets unconnected to the original theft. Llamarisk's joint incident report, published April 20, confirmed 83,471 ETH equivalent spread across seven attacker wallets on Ethereum mainnet and Arbitrum. The report outlined two resolution scenarios: a 15.12% haircut across all restaked ETH holders, producing roughly $123 million in bad debt absorbed by Ethereum core's reserve; or isolating losses at the L2 level, repricing tokens to 26.46% backing and generating about $230 million in bad debt concentrated across Mantle, Arbitrum, and Base, while leaving Ethereum core untouched.
Contagion: DeFi Lending Markets Suffered a Bank Run
Aave alone saw between $6.6 billion and $8.45 billion in outflows. Wrapped ETH pools on Arbitrum, Base, Mantle, Linea, and Plasma hit near 100 percent utilization, effectively blocking withdrawals. At least nine DeFi protocols were classified as directly affected, including Compound, Morpho, Lido, Ethena, Pendle, Euler, Beefy, and Lombard Finance.
Three separate post-mortems have been published by KelpDAO, Layerzero, and Llamarisk, but none agree on where responsibility lies. Layerzero announced April 20 that it would no longer sign or attest messages for any application running a one-of-one DVN configuration, pushing a protocol-wide migration to multi-verifier setups. Kelp maintains that Layerzero's default configuration shipped with single-source verification across Ethereum, BNB Chain, Polygon, Arbitrum, and Optimism, and that allegedly 40% to 50% of all Layerzero OFT applications currently use the same one-of-one setup.
Hoskinson: Cross-Chain Verification Failures Are the New Primary Threat Vector
In a video published from Wyoming, Charles Hoskinson walked viewers through the incident, saying, “The standard DeFi threat model assumes smart contract bugs are the dominant risk. That’s not true anymore.” He noted a 46-minute window between the initial drain and Kelp's emergency pause, demonstrating that incident response cannot outrun the speed at which stolen assets can be deployed into lending markets.
“What makes this novel is the contagion,” Hoskinson explained. “It spread to lending, which then created bad debt contagion inside these lending protocols. It created a bank run, and we saw $13 billion of TVL pulled in a very short period of time for a $290 million hack. That’s a crisis of confidence.” He framed Cardano's lower exposure as a function of its liquid, non-custodial staking design, which removes the need for the staking-to-liquid-staking-to-restaking wrapper chain that created the attack surface at Kelp.
Hoskinson highlighted Midnight, Cardano's privacy-focused sidechain, as a solution. Its Nightstream protocol folds entire chain states into proofs that travel alongside cross-chain messages, making forged messages verifiable before acceptance. Multi-party computation support on Midnight would allow Layerzero to deploy turnkey two-of-three or five-of-seven DVN configurations with less operational friction. Zero-knowledge proofs would block poisoned messages at the verification layer, and network anonymization would make DDoS components of such attacks harder to execute. He also warned that state-sponsored hacking groups like Lazarus are increasingly using frontier AI models, accessed through bribed insiders at major AI labs, to scan entire codebases for emergent vulnerabilities. “Hacks are a part of life,” he said, “and they’re going to get much, much worse for everyone.”

