AAVE
DEFI
ZRO
READ
AVAX
A security exploit targeting KelpDAO, the liquid restaking protocol, has been reported, prompting incident statements from both LayerZero and the Aave governance community. Details remain limited and partially unverified, but the reports point to a breach affecting rsETH, KelpDAO's restaked ETH token.
LayerZero published an incident statement addressing the KelpDAO situation. Separately, an rsETH incident report dated April 20, 2026 appeared on the Aave governance forum, indicating the exploit had cross-protocol implications.
The exact scope of losses, the attack vector, and whether user funds were directly drained have not been independently confirmed at the time of writing. Readers should treat early figures circulating on social media as unverified until the KelpDAO team or an independent security auditor publishes a full post-mortem.
The timeline suggests the incident surfaced around April 20, with both LayerZero and Aave community members responding within days. Whether KelpDAO paused deposits or withdrawals in response has not been formally confirmed in the available evidence.
KelpDAO operates as a liquid restaking protocol, allowing users to deposit staked ETH and receive rsETH, a liquid token representing their restaked position. This model lets holders maintain liquidity while earning additional yield through restaking infrastructure.
The protocol's integrations across DeFi, including with lending platforms like Aave and cross-chain messaging layers like LayerZero, mean that a security incident in KelpDAO can ripple outward. The Aave governance report specifically focused on rsETH, suggesting the exploit may have affected how the token interacted with lending markets. In an environment where DeFi protocols are increasingly interconnected, security events like this highlight the risks that come with composability, a concern that extends well beyond any single protocol. Recent legislative efforts, such as those where Treasury Secretary Bessent urged Congress to pass digital asset legislation, underscore the growing regulatory attention on DeFi security standards.
Users holding rsETH or with positions in protocols that accept rsETH as collateral should monitor official KelpDAO channels for updates on whether withdrawals or redemptions have been paused or restricted.
The key milestones to watch include: a formal post-mortem from the KelpDAO team detailing the attack vector and losses; any compensation or recovery plan for affected users; and whether integrated protocols like Aave adjust risk parameters for rsETH in response. The broader crypto market continues to develop rapidly, with new products like the Bitwise Avalanche ETF recently launching on the NYSE, but security incidents remain a persistent challenge for DeFi adoption.
Until a verified post-mortem is published, users should avoid interacting with KelpDAO contracts and treat any unsolicited recovery or refund links as potential phishing attempts.
Has the KelpDAO exploit been fully confirmed?
Not yet. The article uses "reported" language because, while incident statements have been published by LayerZero and on the Aave governance forum, a complete post-mortem with verified loss figures and attack details has not been released.
What is rsETH?
rsETH is KelpDAO's liquid restaking token. Users deposit staked ETH into KelpDAO and receive rsETH, which can be used across DeFi while the underlying ETH continues earning restaking rewards.
What should KelpDAO users do right now?
Monitor official KelpDAO communication channels for updates on fund security, withdrawal status, and any recovery plans. Avoid clicking links claiming to offer refunds or fund recovery, as these are common phishing tactics following exploit reports.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making any investment decisions.
Read original article on trustscrypto.com