rsETH Depegs After $28M Hack, Flare CPO Calls for New Bridge Security Standards

rsETH Depegs After $28M Hack, Flare CPO Calls for New Bridge Security Standards

N
News Editor 01
2026-07-09 13:39:13
KelpDAO's rsETH depegged following a suspected North Korean-linked hack, with over $70M stolen. Flare CPO Filip Koprivec argues bridge security must be integrated into collateral risk management. Flare is advancing FAssets v1.3 upgrades and expanding validator networks to address systemic DeFi risks.
rsETHKelpDAOBridge SecurityDeFiHacker Attack

On April 23, the liquid restaking token rsETH issued by KelpDAO lost its peg to Ethereum (ETH) after a suspected North Korean-backed hack, plunging to $1,723 while ETH traded near $2,270 — a spread of over $540. Although the token has partially recovered, the discount remained between $150 and $200 as of April 23. According to CoinGecko, rsETH trading volume shrank from multi-million levels on April 18-19 back to five figures, reflecting lingering market unease.

Attack Details and Contagion

The hack drained approximately $280 million in crypto from Ethereum and Arbitrum (per analyst ZachXBT), with about $71 million frozen by the Arbitrum Security Committee. KelpDAO stated on X that all efforts are now focused on user protection and protocol hardening. However, the depegging triggered forced liquidations on platforms like Morpho, Spark, and Gearbox due to falling collateral values. To prevent bad debt, Aave froze rsETH and wrsETH reserves and set loan-to-value ratios to zero on April 23.

Flare CPO: Bridge Security as Collateral Risk Core

Filip Koprivec, Chief Product Officer at Flare, told Bitcoin.com News that the rsETH incident highlights a shared responsibility between asset issuers and hosting protocols. “When a protocol lists a bridged asset as collateral, it inherits not only token risk but also bridge risk,” Koprivec said. He argued that bridge security must be treated as part of collateral risk management from the outset, not as an afterthought. Koprivec urged protocols to present bridge security configurations transparently — such as whether the path is genuinely decentralized, if the configuration can be changed, and how changes are communicated — rather than burying them in technical documentation. He called for continuous auditing rather than one-time disclosures.

Flare’s Response and Market Metrics

In the wake of the attack, Flare suspended its LayerZero OFT transfer rail as a precaution and expanded its decentralized verifier network (DVN) from two to four — now including LayerZero Labs, Nethermind, Canary, and Horizen. The network is also preparing a FAssets v1.3 upgrade that will introduce minting controls like caps and time delays. Flare noted that while most of the industry still relies on fragile bridge configurations, its own DeFi ecosystem has maintained a total value locked (TVL) of over $440 million, with the majority of FXRP actively deployed — underscoring market appetite for more secure bridging infrastructure.

The KelpDAO incident serves as a stark reminder that bridge security is no longer optional but foundational to DeFi resilience. Whether it will catalyze industry-wide standards for transparent and robust bridging remains to be seen.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.