Skip to content
PROTOCOL RESEARCH

KernelDAO (Kelp) risk

Kelp rsETH suffered a ~$292M unbacked-mint bridge exploit in April 2026 (largest DeFi hack of the year); backing was restored to ~100% by an Aave-led rescue coalition, but the recent nine-figure fund-loss event gates this to avoid until the reworked bridge earns a fresh track record.
AvoidResearched Jul 1, 2026
watch: Audits & contractsCore rsETH contracts were audited by Sigma Prime (multiple assessments, incl. the rsETH adapter) and Code4rena (Nov 2023) and were not the failure point; the loss came from off-chain bridge verifier infra, and I could not confirm a published re-audit of the reworked CCIP bridge this run.
weak: Admin controlCore governance is strong (6/8 multisig + 10-day timelock), but that never covered the cross-chain bridge; a Kelp config change downgraded the bridge DVN from 2-of-2 to 1-of-1, creating the exact single point of failure the exploit walked through.
weak: OracleThe cross-chain message verifier was a 1-of-1 LayerZero DVN; attackers poisoned its RPC feed and forged a lock message, so the effective supply oracle was a single point of failure that minted ~116,500 unbacked rsETH.
weak: Liquidity & exitDuring the incident withdrawals were paused across 20+ chains and Aave, Spark, Fluid and Upshift froze rsETH; backing is back above 100% and markets reopened across five networks, but a full freeze happened roughly three months ago.
strong: Yield (real vs emission)Yield is real ETH staking plus EigenLayer restaking rewards, not token emissions; the risk here is principal/backing, not fake APR.
watch: Holder concentrationrsETH supply fell to ~502k after the exploit; on-chain top-holder distribution not pulled this run (Etherscan holder endpoint is Pro-gated).
weak: Track record~$292M unbacked mint in April 2026, the largest DeFi exploit of the year, crystallizing ~$190M of borrowing and $123-230M of potential Aave bad debt; recovery was clean but the event is recent.
🟢 strong🟡 watch / caveat🔴 weak / fund-loss risk
Verdict is a gate (worst flaw wins), not an average. Our read, not financial advice.
auto-sourced now
TVL$886.8M
30d±0%
Audits2
Last hack$293.0M · Apr 2026

DeFiLlama + our exploits feed. Cross-check the dated report against today.

TL;DR

Kelp issues rsETH, a liquid restaking token: you deposit ETH or LSTs, Kelp routes it through EigenLayer, you hold a tradeable claim. The core staking contracts are not where the money was lost. On April 18, 2026 an attacker forged a cross-chain message on rsETH's LayerZero bridge, which was running a single (1-of-1) verifier, and minted roughly 116,500 rsETH with no ETH behind it, about $292M and near 18% of supply. Most of it was pushed into Aave as collateral (about 89,567 rsETH) to borrow ~$190M, leaving Aave modeling $123M to $230M of potential bad debt. This was the largest DeFi exploit of 2026. Backing was later restored to just above 100% by an Aave-led rescue coalition (DeFi United, which raised over $300M in ETH), and markets reopened across five networks by late May 2026. No smart-contract bug was found; the contracts did exactly what they were told by a lie.

Checklist

Audits & contracts. The core rsETH protocol was audited by Sigma Prime (multiple assessments, including the rsETH adapter and LRT updates) and by Code4rena (a Nov 2023 contest). Those contracts performed as written and were not the failure point. The loss lived in off-chain bridge verifier infrastructure. I could not confirm a published third-party re-audit of the reworked Chainlink CCIP bridge this run, so treat the post-fix bridge as refresh. Admin control. Core governance is genuinely strong: a 6/8 multisig plus a 10-day timelock on upgrades. The problem is that this shield never extended to the cross-chain bridge, and a Kelp-side configuration change had downgraded the bridge verifier from 2-of-2 to 1-of-1, manufacturing the single point of failure. Good governance on the wrong perimeter, plus a config choice that removed the redundancy. Oracle. The effective "supply oracle" for bridged rsETH was one LayerZero DVN (1-of-1). Attackers compromised the RPC nodes it relied on and DDoS'd the rest, then injected a synthetic message claiming rsETH had been locked on the source chain. A single verifier deciding whether new tokens are backed is a single point of failure, and it failed. Liquidity & exit. During the incident, withdrawals were paused across 20+ chains and Aave, SparkLend, Fluid and Upshift froze rsETH. Mainnet rsETH stayed backed by real EigenLayer deposits, but bridged L2 rsETH lost its clean 1:1 redemption claim for weeks. As of late May 2026 backing is above 100% (dashboard showed 100.01%) and Aave markets reopened across Ethereum, Arbitrum, Base, Linea and Mantle. Yield: real vs emission. The yield is real: ETH consensus staking plus EigenLayer restaking rewards. This is not an emissions trap. The danger with Kelp is not fake APR, it is whether every rsETH is actually backed by ETH, which is the exact property the exploit broke. rsETH also inherits EigenLayer and AVS slashing exposure on the restaked ETH. Holder concentration. Circulating rsETH is about 502k after the exploit shrank supply. I did not pull the on-chain top-holder table this run (the Etherscan holder endpoint is Pro-gated), so distribution is refresh. Track record. One catastrophic event, and a recent one. ~$292M minted from nothing, ~$190M borrowed against it, $123-230M of potential Aave bad debt, the biggest DeFi hack of 2026, roughly three months before this report. The recovery was impressive and users were made whole, but a clean rescue does not erase that the fund-loss surface actually failed at nine-figure scale.

Worst case

A bridge or verifier weakness lets unbacked rsETH exist again, and rsETH depegs from ETH. That is not hypothetical here, it is the documented April 2026 outcome. If you hold rsETH as collateral when it happens, your position can be liquidated against a token that is quietly worthless, and lending markets freeze exactly when you want to exit. Last time a rescue coalition backfilled the hole, but that was a discretionary bailout, not a guarantee. There is no standing insurance fund that promises a repeat.

Bottom line

Avoid, for now. The core restaking design is sound and the yield is real, and management's incident response (pause 46 minutes after the drain, reverting two follow-up attempts worth ~$100M more, coordinating a $300M+ refill) was genuinely strong. But this is a worst-flaw-wins call, not an average. The fund-loss surface failed for ~$292M three months ago, the fix (Chainlink CCIP migration, LayerZero moving off 1-of-1 DVN configs) is real but not something I could confirm as independently re-audited this run, and there is no insurance backstop. For real capital, this needs a clean post-fix track record and a published bridge re-audit before it moves off avoid. Revisit at next refresh.

Data appendix

  • TVL / supply: DeFiLlama protocol TVL ~$871.6M (slug kelp, live 2026-07-01), matching CoinGecko rsETH market cap ~$873M / circulating ~502,227 rsETH at ~$1,738 (live 2026-07-01). Supply fell sharply after the April 2026 exploit; ATH price ~$5,190 (Aug 2025), now ~67% below ATH.
  • Incident: ~$292M (~116,500 rsETH, ~18% of supply) minted unbacked on 2026-04-18 via a forged message on a 1-of-1 LayerZero DVN bridge (downgraded from 2-of-2 by a Kelp config change); ~89,567 rsETH supplied to Aave to borrow ~$190M; Aave exposure modeled at $123M-$230M. Attributed to Lazarus Group / TraderTraitor. Sources: Chainalysis, LayerZero incident report, The Block, CoinDesk, Messari, The Defiant.
  • Recovery: Aave-led DeFi United coalition raised $300M+ (reported $317-320M) in ETH; final tranche 20,373.72 rsETH into the OFT adapter; recovery completed ~2026-05-25 with backing ~100.01%; Aave and rsETH markets reopened across five networks. Sources: AMBCrypto, CryptoTimes, The Block, Crowdfund Insider.
  • Remediation: LayerZero to stop servicing 1-of-1 DVN configs (moving to 3-of-3 minimum, 5-of-5 where possible); Kelp migrating the rsETH bridge from LayerZero OFT to Chainlink CCIP. Independent re-audit of the reworked bridge: refresh (not confirmed this run).
  • Audits (pre-incident, core protocol): Sigma Prime (multiple assessments, incl. rsETH adapter and LRT updates, audit PDFs on kerneldao.com) and Code4rena (Nov 2023 contest, $28k pool). No smart-contract bug was implicated in the exploit.
  • Admin/governance: Reported 6/8 multisig + 10-day timelock on core protocol (secondary sources; on-chain Safe/timelock addresses not independently re-verified this run). Bridge was outside this control and had been downgraded to 1-of-1 DVN at time of exploit.
  • Oracle: Cross-chain verification was a single LayerZero DVN (1-of-1) at time of exploit.
  • Holder concentration: refresh (Etherscan top-holder endpoint Pro-gated this run).
  • EigenLayer slashing: rsETH inherits EigenLayer/AVS slashing exposure on the restaked ETH; magnitude and current AVS set: refresh. Maintained monthly. Methodology: DeFi Research Instruction v2.

← all protocols