DEFENCE / RADAR

Public snapshot

KelpDAO·Crypto / Web3·

Crypto assets were stolen.

The excerpt reports a confirmed bridge drain of approximately $292 million and attributes the failure to off-chain message-verification infrastructure. The attached record does not establish the complete downstream scope.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Confirmed exploitation
Mechanism
Reported cause: single-verifier 1-of-1 DVN configuration
Consequence
Reported: Crypto assets were stolen.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
KelpDAO
Industry
Crypto / Web3
Disclosed
Event date
Affected asset
LayerZero Labs DVN and KelpDAO rsETH bridge
Data involved
Crypto Assets
Reported impact
Asset theft
Attached evidence
8 independent domains · 8 sources

2)Evidence-backed incident path

  1. 01

    Reported cause

    single-verifier 1-of-1 DVN configuration

    ConfidenceSecondary
    Exact excerpt

    a direct consequence of their single-DVN setup

    layerzero.network · Apr 19
    E1
  2. 02

    Reached

    LayerZero Labs DVN and KelpDAO rsETH bridge

    ConfidenceSecondary
    Exact excerpt

    The subject of this highly-sophisticated attack was the poisoning of the downstream RPC infrastructure used by the LayerZero Labs DVN

    layerzero.network · Apr 19
    E2
  3. 03

    Observed

    Crypto assets were stolen.

    ConfidenceProbable
    Exact excerpt

    stole ~$292 million (116,500 rsETH)

    chainalysis.com · Apr 23
    E3

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • Primary confirmation is not supplied in the source list
  • That a Defence review would have prevented this incident

4)Relevance to your product

A single protocol invariant can carry the weight of the complete asset path.

This pattern applies when…

  • Products that depend on external verifiers, bridges, or message-authentication infrastructure.

Diagnostic questions

  1. Do value and authorization invariants hold across every contract path?
  2. Can one actor manipulate pricing, accounting or bridge state out of sequence?
  3. Are privileged operations bounded under adversarial composition?

This incident does not establish your product's risk.

5)Sector context — Crypto / Web3

126 incident threads in the 365-day public record
  1. 0 incident threads
  2. 1 incident threads
  3. 1 incident threads
  4. 0 incident threads
  5. 15 incident threads
  6. 15 incident threads
  7. 6 incident threads
  8. 15 incident threads
  9. 17 incident threads
  10. 14 incident threads
  11. 16 incident threads
  12. 26 incident threads
Same incident family
98
Protocol exploit
Confirmed share
14%
18 confirmed · 108 reported
Display family
Vulnerability exploitation
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Crypto / Web3 in Radar →

6)Defence control mapping

Context-only control area

Protocol and contract control area

  • Do value and authorization invariants hold across every contract path?
  • Can one actor manipulate pricing, accounting or bridge state out of sequence?
  • Are privileged operations bounded under adversarial composition?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.
  • This control is outside the current public external web/API review offer.

7)Public evidence ledger

8 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E3
    chainalysis.comInside the KelpDAO Bridge ExploitSecurity research · Apr 23 · Cited
    Security researchCited
    Exact excerpt
    stole ~$292 million (116,500 rsETH)
  2. E1, E2
    layerzero.networkKelpDAO Incident Statement | LayerZeroOther public report · Apr 19 · Cited
    Other public reportCited
    Exact excerpt
    a direct consequence of their single-DVN setup
  3. S3
    blockaid.ioHow a Single LayerZero DVN Compromise Drained $292M from KelpDAO | Blockaid BlogOther public report · Apr 19 · Attached
    Other public reportAttached
    Exact excerpt
    KelpDAO has since paused rsETH transfers on Ethereum
  4. S4
    trendingtopics.eu$292 Million DeFi Heist Sends Shockwaves Through KelpDAO, Aave, and ArbitrumOther public report · Apr 21 · Attached
    Other public reportAttached
  5. S5
    dextools.ioKelp DAO hit by $293M hack: biggest DeFi theft of 2026. | DEXTools NewsOther public report · Apr 22 · Attached
    Other public reportAttached
  6. S6
    crypto.newsKelpDAO $290M Hack Wipes $13B From DeFiOther public report · Apr 22 · Attached
    Other public reportAttached
Show all 8 sourcesShow the first six sources
  1. S7
    spotedcrypto.comKelpDAO $292M Hack: Lazarus Group Confirmed | Spoted CryptoOther public report · Apr 28 · Attached
    Other public reportAttached
  2. S8
    thecentralbulletin.comKelpDAO Was Drained for $292 Million. DeFi Is Still Standing. Here Is Why. - The Central BulletinOther public report · May 01 · Attached
    Other public reportAttached

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →