Skip to content

KelpDAO Exploit Post-Mortem: How Funds Absorbed a $292M Shock

KelpDAO Exploit Post-Mortem: How Funds Absorbed a $292M Shock

On April 18, 2026, KelpDAO’s rsETH bridge infrastructure was exploited through its LayerZero OFT implementation, resulting in approximately 116,500 rsETH being fraudulently minted and released.

Rather than selling the stolen tokens immediately, the attacker deposited the rsETH as collateral across DeFi lending protocols, most notably Aave, to borrow real ETH liquidity.

By the end of the exploit, the attacker had extracted roughly $292 million.

Most readers already know the headline.

What’s more interesting is how protocols, funds, and vault curators reacted to preserve their balance sheets and protect investors.

The first public report of the exploit appeared on X at 7:41 PM UTC.

First Public Report

Not long afterward, it became apparent that Aave had also been affected.

Aave’s shared liquidity architecture, which normally improves capital efficiency, became one of its largest sources of systemic risk.

The protocol was suddenly exposed to potential bad debt across multiple lending markets.

As news spread, depositors rushed to withdraw WETH liquidity.

Second Public Report

Several markets quickly reached 100% utilization, leaving no remaining liquidity for withdrawals and effectively trapping users who hadn’t exited quickly enough.

How Protocols, Funds, and Curators Responded

Section titled “How Protocols, Funds, and Curators Responded”

The exploit became an unfortunate real-world stress test for reserve funds, risk frameworks, and treasury management.

Yuzu had no direct rsETH exposure.

However, second-order effects pushed several underlying strategies into negative carry.

By April 24, the reconciled loss totaled $168,167.83, which was entirely allocated to the junior tranche (yzPP).

Junior NAV declined from $1.1376 to $1.0902 per unit, a 4.17% reduction.

Senior vault holders (yzUSD and syzUSD) experienced no losses.

Yield distributions during the affected period were fully funded by Yuzu’s Reserve Fund, and redemptions resumed immediately following the loss allocation.

The architecture functioned exactly as intended: junior capital absorbed the risks it had been compensated to bear.

Avant operates a senior/junior tranche structure (savAssets and avAssetX) supported by a dedicated Reserve Fund.

That Reserve Fund is capitalized through protocol revenue and secured within MPC wallets, serving as an explicit first-loss layer for third-party protocol failures.

The KelpDAO exploit was precisely the type of scenario it was designed to address.

Avant temporarily paused its LayerZero OFT bridges from Movement while evaluating exposure.

Neither senior nor junior depositors experienced losses because the Reserve Fund fully absorbed the impact.

Lido’s EarnETH vault adopted a similar strategy using a smaller protection buffer.

The vault held approximately 9% direct exposure to rsETH, representing around $21.6 million in TVL.

The Lido DAO activated a $3 million first-loss protection mechanism, burning DAO-owned vault shares before any realized losses reached users.

EtherFi’s Liquid Vaults similarly committed to absorbing losses internally.

Despite elevated borrowing costs caused by disruption in Aave markets, EtherFi publicly stated that vault users would not experience NAV drawdowns.

Ethena maintained zero rsETH exposure throughout the incident.

The protocol published an updated Proof of Reserves ahead of schedule, confirming 101.2% collateralization for USDe.

As a precaution, Ethena temporarily paused LayerZero OFT bridging from Ethereum while investigating the exploit.

Users could continue minting, redeeming, and staking USDe throughout the event.

Bridging resumed once the underlying issue had been assessed.

Although unaffected directly, Midas paused all mToken minting and redemption activity on April 18 as a precautionary measure.

Normal operations resumed gradually on April 19 after the situation became clearer.

RockawayX implemented similar protective measures.

The firm confirmed zero rsETH exposure across its Kamino and Morpho vault strategies while temporarily limiting activity until risks had been assessed.

Aave already maintains a Safety Module designed for situations involving protocol losses.

However, because this exploit involved fraudulently minted assets bridged onto Ethereum, there was initially uncertainty regarding whether losses would qualify for reserve coverage.

Ultimately, the broader DeFi ecosystem coordinated through DeFi United to assemble a voluntary recovery package.

The effort included an Aave DAO proposal contributing 25,000 ETH toward covering the remaining shortfall.

The exploit undoubtedly shocked the DeFi ecosystem.

It also demonstrated that thoughtfully designed risk-management frameworks can work exactly as intended.

The protocols and funds that emerged with minimal investor impact all shared one characteristic:

They had pre-funded loss-absorption mechanisms in place before the crisis occurred.

Reserve funds, junior capital tranches, treasury buffers, and similar structures exist because exploits and liquidity crises are not a matter of if, but when.

Perhaps even more importantly, transparent communication and timely financial reporting proved essential in maintaining investor confidence.

In moments of market stress, near-real-time access to a fully traceable:

  • Balance Sheet
  • Profit & Loss Statement
  • Net Asset Value (NAV)

is quickly becoming table stakes rather than a competitive advantage.

That’s precisely the problem PennyWorks is built to solve.

Crises have a way of separating the prepared from the improvising.

Reserve funds and treasury mechanisms are valuable, but they only work if the accounting behind them is equally reliable.

For fund managers, that means having trusted, independent NAV computation and financial reporting available in near real time.

When investors, auditors, or LPs need answers, accurate books allow everyone to make informed decisions without delay.