TL;DR
Kelp issues rsETH, a liquid restaking token: you deposit ETH or an LST, Kelp routes it through EigenLayer, you hold a tradeable claim. On April 18, 2026 an attacker forged a cross-chain message on rsETH's LayerZero bridge and minted roughly 116,500 rsETH with nothing behind it, about $292M. No smart contract broke. The bridge ran a single verifier, attackers poisoned the RPC nodes it depended on, and the contracts obeyed a lie.
Four months on, the repair is real in the places you can measure, and this run measured them. The on-chain NAV oracle reports 1.077751 ETH per rsETH; multiplied by live supply that implies 462,144 ETH of assets, about $869.5M, which lands within 1.1% of the $860.06M DefiLlama computes independently from the deposit contracts. The market prices rsETH at 1.074752 ETH, a 0.28% discount to that NAV. Nobody is pricing in a hole. The deposit pool is unpaused and redemption works.
I also settled the governance question the last two runs left open, and it cuts both ways. Every core proxy sits behind a 10-day timelock whose proposer is a 6-of-11 Safe, better than the 6-of-8 secondary sources report. But the admin change that actually caused the loss, a bridge verifier downgraded from two required verifiers to one, sat behind none of it.
What has not recovered is the asset's standing. Aave still has rsETH frozen at 0% LTV today. Deposits are down about a third in token terms since the exploit.
Checklist
Audits & contracts. Better documented than the last run concluded. DefiLlama links Kelp's GitBook audits page, which returns 404, but the reports themselves are live on kerneldao.com and I opened five of them: "KELP DAO LRT, Smart Contract Updates" (v2.0, June 2024), "KELP DAO LRT-ETH Withdrawals" (v2.1, June 2024), "Kelp DAO PEPE Upgrade Integration" (v2.0, September 2024), "Kelp DAO rsETH Adapter" (v2.0, November 2024) and "Kelp June Upgrades" (v2.1, June 2025), all by Sigma Prime, plus a Code4rena contest that ran November 10 to 15, 2023 with a $28,000 pool. Two cautions. The one titled "rsETH Adapter" scopes an ERC-4626 vault adapter, not the LayerZero OFT bridge adapter, so it is easy to mistake for a bridge audit and it is not one. And the newest report is June 2025, ten months before the exploit; nothing has been published since. The reworked CCIP bridge is refresh.
Admin control. This is where the last run and I disagree, and the disagreement is the point. The verified facts are good: the rsETH token, the LRTDepositPool, the LRTConfig and the LRTOracle are all EIP-1967 proxies sharing one ProxyAdmin at 0xb61e0e39b6d4030c36a176f576aabe44bf59dc78, owned by a TimelockController at 0x49bd9989e31ad35b0a62c20be86335196a3135b1 whose getMinDelay() returns 864,000 seconds, exactly 10 days. The proposer and canceller is a Safe v1.3.0 at 0xb3696a817d01c8623e66d156b6798291fa10a46d with getThreshold() of 6 over 11 owners. Admin of the timelock is the timelock itself, so there is no external key that can shorten the delay. That is better than most of what we rate solid, and better than the 6-of-8 that gets repeated secondhand.
None of it touched the thing that broke. LayerZero's incident report states that "a previous 2-of-2 configuration had been modified by the application owner to a 1-of-1 configuration which used only the LayerZero Labs DVN." Kelp disputes the framing, says 1-of-1 was LayerZero's documented default, says LayerZero staff approved it during the L2 expansion, and notes that roughly 47% of LayerZero applications ran 1-of-1 at the time. LayerZero later reversed three weeks of blame and apologised: "We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions," adding it "didn't police what our DVN was securing." Both are partly right and it does not help you. A single configuration switch on Kelp's perimeter, guarded by nothing, cost $292M. Grading this yellow because a different perimeter is well governed would be averaging where the worst flaw wins. Red, and it stays red until bridge and messaging configuration demonstrably sits behind the same timelock as everything else.
Oracle. Two different things get called an oracle here and only one of them broke. The NAV oracle is fine, and I checked it against something independent rather than taking its word: LRTOracle reports 1.077751 ETH per rsETH, which across the 428,804 rsETH supply implies about $869.5M of assets, within 1.1% of DefiLlama's independently computed $860.06M. The thing that failed was the cross-chain supply oracle, a single verifier deciding whether new tokens were backed. Kelp is moving to Chainlink CCIP, and LayerZero's own DVN now refuses 1/1 configurations, defaults to 5/5 where feasible with a 3/3 minimum, and has raised its signer threshold from 3-of-5 to 7-of-10. The specific defect is being closed from two independent directions. Whether the migration is finished across every chain rsETH lives on is refresh.
Liquidity & exit. This is where the recovery story stops. I read Aave V3's live reserve configuration for rsETH on Ethereum today, through two data providers with identical results: LTV 0.00%, borrowing disabled, isFrozen true. Existing positions keep a 75% liquidation threshold and a 107.50% liquidation bonus, so nobody gets force-liquidated, but no new collateral value is granted and no new supply accepted. The May 2026 "Aave restores limits" headlines were about WETH, not rsETH, and they are easy to read the wrong way. Aave's proposed post-incident framework scores native rsETH 9 of 14 (Tier 3, frozen, with a 68% eMode cap against the 93% it once held) and the bridged wrsETH 12 of 14 (Tier 4, collateral eligibility permanently revoked, existing holders keep exit rights). Direct redemption from Kelp does work, in 7 to 10 days, which includes EigenLayer's 7-day delay. So you can get out. You just cannot use the asset the way you used to, and the most sophisticated risk team in DeFi has spent sixteen weeks deciding not to re-enable it.
Yield: real vs emission. ETH consensus staking plus EigenLayer restaking rewards. Nothing here is an emissions mirage, and that has never been the concern with Kelp. The concern is whether every rsETH is backed, which is precisely the property that broke. rsETH also carries layered slashing exposure: Ethereum consensus slashing plus slashing on every AVS its operators secure. The current AVS set and the size of that exposure are refresh.
Holder concentration. I could not pull it, same wall as last time. Etherscan's tokenTopHolders endpoint is Pro-gated and Nansen's top-holders call returned 403 for premium labels. What I can see is the direction of supply: 428,804 rsETH now against about 502,227 on 2026-07-01, down 14.6% in roughly six weeks. Distribution itself is refresh.
Track record. One catastrophic event, and it is recent. About $292M minted from nothing on 2026-04-18, attributed by Chainalysis to DPRK's Lazarus Group through its TraderTraitor sub-group. It is usually called the largest DeFi exploit of 2026 and that is contestable: DefiLlama's own hacks table puts Drift Trade at $295.0M on 2026-04-01 against Kelp's $293.0M seventeen days later, while Drift's loss is variously reported between $285M and $295M. Two of the three worst DeFi losses of the year happened in the same eighteen days and Kelp is one of them; which one is first does not change anything. Kelp's response was genuinely good: the pauser multisig froze core contracts at 18:21 UTC, 46 minutes after the drain, and two follow-up transactions at 18:26 and 18:28 attempting a further 40,000 rsETH were rejected because the protocol was already paused. The Arbitrum Security Council froze 30,766 ETH, about a quarter of the drain, on April 20. But the hole was filled by a discretionary coalition, not a standing backstop, and the fill was not even: mainnet holders were largely protected while holders on bridged chains reportedly took selective impacts.
Worst case
Unbacked rsETH exists again and the token depegs from ETH. That is not a thought experiment for this protocol, it is what happened in April, and the perimeter it happened on is still the perimeter with the least governance around it. If you hold rsETH as collateral when it recurs, you can be liquidated against a token nobody will price, and the venues you would exit through freeze at exactly the moment you need them. Last time a rescue coalition raised $327.95M to refill the gap, roughly four times what was needed, and Aave's own funding proposal still showed a residual gap of about 75,081 ETH at the time it was written. That was goodwill plus systemic self-interest, not an obligation, and a second time would be asking the same protocols to bail out the same asset. The quieter and more likely case is that nothing explodes: no new exploit, just a token that stays structurally demoted, unusable as good collateral, slowly bleeding deposits, while you hold something that only redeems at NAV on a 7 to 10 day queue.
Bottom line
Avoid, and this time mostly for reasons I measured rather than inherited. The parts that recovered genuinely recovered, and they deserve to be said plainly: the on-chain NAV cross-checks against independently computed TVL within about 1%, the market prices rsETH within 0.3% of that NAV, the pool is unpaused, redemption works, the yield is real, and the core contracts sit behind a 10-day timelock with a 6-of-11 Safe in front of it. If the verdict rested only on whether rsETH is worth what it claims to be worth, it would move today.
It does not rest there. A nine-figure loss on the fund-loss surface four months ago, caused by a configuration change that no timelock and no threshold stood in front of, with nothing published since showing that perimeter has been brought inside the governance that protects everything else. A replacement bridge I cannot confirm anyone has audited, from a protocol whose newest published audit predates the exploit by ten months. Bridged holders who ate losses while mainnet holders did not. And Aave still holding the asset at 0% LTV today. Deposits tell the same story: stETH down 39.5%, ETHx down 41.4% since the exploit. The market has not come back either.
Three things would move this to caution, and all three are checkable rather than judgment calls. A published independent audit of the CCIP bridge, together with evidence that messaging configuration now sits behind the timelock. Aave restoring a non-zero LTV on native rsETH. And two more quarters without incident.
Data appendix
- TVL: $873.30M (
api.llama.fi/tvl/kelp) and $874.48M (api.llama.fi/tvl/kernelDAO), effectively the same book, verified earlier today. A later same-day re-read of the same endpoints returned $860.06M and $861.24M as ETH slipped about 1%; this book is almost entirely ETH-denominated, so USD TVL is largely an ETH price proxy. Percentages below use $873.30M. Note the slug trap: our file slug iskelp-daoandapi.llama.fi/tvl/kelp-daoreturns "Protocol not found", as doeskelpdao; the parent record isparent#kelp-daowith slugkerneldao. 90d: $1,554.0M on 2026-05-13, down 43.8%. 30d: $930.2M on 2026-07-12, down 6.1%. ATH $2,094.2M on 2025-09-18, down 58.3%. - Deposits are leaving, and it is not just ETH price. DefiLlama's token breakdown, 2026-04-15 to 2026-08-10: stETH 435,474 to 263,264 (down 39.5%), ETHx 85,688 to 50,180 (down 41.4%), ETH 154,517 to 143,887 (down 6.9%).
- Peg and backing (verified this run): on-chain NAV via
LRTOracle.rsETHPrice()at 0x349A73444b1a310BAe67ef67973022020d70020d = 1.077751 ETH. Market 1.074752 ETH (CoinGecko), ETH at $1,881.54, rsETH at $2,022.19. Discount to NAV 0.28%, a normal LRT secondary spread. Backing cross-check: 428,804.31 rsETH x 1.077751 = 462,144 ETH implied assets, about $869.5M, versus DefiLlama's independently computed $860.06M, a 1.1% gap. rsETH ATH $5,190.42 on 2025-08-24, down 61.0% (mostly ETH price). - Supply:
totalSupply()428,804.31 rsETH, matching CoinGecko circulating 428,804.3083 exactly. Down 14.6% from about 502,227 on 2026-07-01. - Admin and governance (verified on-chain this run): rsETH 0xA1290d69c65A6Fe4DF752f95823fae25cB99e5A7, LRTDepositPool 0x036676389e48133B63a802f8635AD39E752D375D, LRTConfig 0x947Cb49334e6571ccBFEF1f1f1178d8469D65ec7 and LRTOracle all share ProxyAdmin 0xb61e0e39b6d4030c36a176f576aabe44bf59dc78. Its
owner()is TimelockController 0x49bd9989e31ad35b0a62c20be86335196a3135b1 withgetMinDelay()= 864,000s = 10 days. PROPOSER_ROLE and CANCELLER_ROLE are held by Safe v1.3.0 0xb3696a817d01c8623e66d156b6798291fa10a46d,getThreshold()= 6 over 11 owners, so 6-of-11 and not the 6-of-8 reported secondhand. TIMELOCK_ADMIN_ROLE is held by the timelock itself. EXECUTOR_ROLE is held by address(0), so anyone may execute after the delay, which is normal and is what happens in practice: the three EOAs that executed past batches hold no roles. Upgrade batches executed 2026-01-24, 2025-12-20, 2025-05-11, 2025-04-30 and 2025-04-16; no transaction of any kind has hit the timelock since 2026-01-24, 199 days ago, so nothing has even been scheduled.paused()false on both the deposit pool and the token. - Aave status (verified on-chain this run): rsETH on Aave V3 Ethereum reads LTV 0.00%, liquidation threshold 75.00%, liquidation bonus 107.50%, reserve factor 15.00%, usageAsCollateralEnabled true, borrowingEnabled false, isActive true, isFrozen true. Read via
getReserveConfigurationDataagainst two data providers, identical results. The May 2026 "Aave restores limits" coverage refers to WETH, not rsETH. - Incident: 2026-04-18, about $292M and 116,500 rsETH per Chainalysis; DefiLlama's hacks table records $293.0M and classifies it as a bridge hack. Not a contract bug: a 1-of-1 LayerZero DVN, two internal LayerZero-hosted RPC nodes compromised while external nodes were DDoS'd, poisoned nodes reporting a false burn on Unichain. Attribution DPRK Lazarus Group / TraderTraitor. Pause at 18:21 UTC, 46 minutes after the drain; follow-up attempts at 18:26 and 18:28 for a further 40,000 rsETH were rejected. Arbitrum Security Council froze 30,766 ETH (about $71M, roughly a quarter of the drain) on 2026-04-20. Ranking: DefiLlama puts Drift Trade at $295.0M on 2026-04-01 above Kelp's $293.0M, though Drift's loss is reported between $285M and $295M depending on source, so "largest of 2026" is genuinely contested.
- Recovery: Aave-led DeFi United coalition, $327.95M in ETH raised per the Aave governance forum. Of about 112,103 unbacked rsETH created, roughly 106,993 were recovered (89,567 via Aave liquidations, 17,426 via Compound), leaving about 5,200 rsETH; Aave stated 95.4% recovered within thirty days on 2026-05-18. Final tranche 20,373.7 rsETH on 2026-05-25/26, backing pushed above 100%, recovery rate about 1.07 ETH per rsETH. Aave's ARFC (proposal stage, 2026-04-24) sized the original backing shortfall at about 163,183 ETH with a residual gap of about 75,081 ETH after recoveries, and requested 25,000 ETH from the Aave treasury. Users were not uniformly made whole: mainnet largely protected, bridged chains reportedly took selective impacts.
- Aave collateral damage: Aave V3 TVL fell from $25.95B on 2026-04-18 to $17.54B on 2026-04-20, down 32.4% in 48 hours, and kept falling to $13.73B by 2026-04-26 (DefiLlama, slug
aave-v3). Bad debt was modeled at $123.7M to $230.1M at the time against $221.39M of attacker-posted collateral; those were contemporaneous estimates and the final resolved figure is refresh. - Aave collateral framework: proposed Asset Safety Tier system scores native rsETH 9/14 (Tier 3, frozen pending Kelp adapter recovery, proposed 68% eMode versus the 93% granted under Proposal 311) and wrsETH 12/14 (Tier 4, collateral eligibility permanently revoked across all nine L2 instances, existing holders retain exit rights). Still at TEMP CHECK stage, latest thread activity 2026-07-26; ratification is refresh.
- Remediation: rsETH bridge migrating from LayerZero OFT to Chainlink CCIP and the CCT standard, announced 2026-05-05. LayerZero's incident report says "a previous 2-of-2 configuration had been modified by the application owner to a 1-of-1 configuration"; Kelp disputes the framing and says 1-of-1 was the documented default, approved in integration meetings, and used by roughly 47% of LayerZero applications at the time. LayerZero subsequently reversed and apologised, saying it "made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions" and "didn't police what our DVN was securing." Its DVN no longer services 1/1, defaults to 5/5 where feasible with a 3/3 minimum, and its own signer threshold moved from 3-of-5 to 7-of-10. Independent re-audit of the reworked bridge: refresh.
- Withdrawal path: direct rsETH redemption takes 7 to 10 days, including EigenLayer's 7-day escrow. Withdrawals went live again on 2026-05-15. EigenLayer delegations were unaffected by the exploit.
- Audits (read this run): Sigma Prime, five reports live at kerneldao.com: LRT Smart Contract Updates v2.0 (June 2024), LRT-ETH Withdrawals v2.1 (June 2024), PEPE Upgrade Integration v2.0 (September 2024), rsETH Adapter v2.0 (November 2024, scoping an ERC-4626 vault adapter and not the OFT bridge), June Upgrades v2.1 (June 2025). Code4rena contest 2023-11-10 to 2023-11-15, $28,000 pool. DefiLlama's linked audits page (kelp.gitbook.io/kelp/audits) returns 404. Newest report is June 2025; nothing published post-incident.
- Holder concentration: refresh (Etherscan tokenTopHolders is Pro-gated, Nansen top-holders returned 403 premium_labels).
- Slashing: rsETH carries Ethereum consensus slashing plus AVS slashing on every AVS its operators secure. Current AVS set and exposure size: refresh. Maintained monthly. Methodology: DeFi Research Instruction v2.