Arbitrum disclosed on April 21, 2026, that its Security Council had used an emergency contract upgrade to move approximately 30,765.67 ETH out of an address the organization connected to the KelpDAO exploiter. The ether was transferred to an intermediary wallet from which it could be moved only through a further Arbitrum governance action.
The Arbitrum One transaction was recorded at 03:35:08 UTC on April 21, corresponding to late April 20 in the Eastern time zone. Arbitrum’s public announcement and technical account appeared on April 21, making the intervention the defining development for the archive date even though the operation began before midnight in the United States.
How the council moved the ether
Arbitrum’s technical account said contributors prepared an atomic operation that temporarily upgraded the network’s Inbox contract on Ethereum. The temporary implementation added a function capable of constructing a cross-chain transaction that acted as though it came from the exploiter-linked address. That transaction sent the ether to address 0x0000000000000000000000000000000000000DA0 on Arbitrum One.
The council then restored the Inbox contract’s original implementation. The corresponding Ethereum transaction was successful at 03:26:47 UTC, while the resulting Arbitrum One transfer was confirmed several minutes later. Arbitrum said council members verified the payload before signing and executing it.
This was not an ordinary token transfer authorized with the address holder’s private key. It relied on the Security Council’s authority to upgrade core system contracts during an emergency. Arbitrum characterized the destination as a frozen intermediary wallet and said releasing the balance would require a subsequent governance action coordinated with relevant parties.
The KelpDAO incident behind the action
The intervention followed an April 18, 2026, incident involving KelpDAO’s cross-chain rsETH route. A contemporaneous report prepared by Aave service providers said a forged inbound packet from Unichain was accepted through a route configured with one required decentralized verifier network. No corresponding source-chain burn had occurred, yet 116,500 rsETH was released from an Ethereum-side adapter.
The Aave report said the recipient distributed the rsETH among seven addresses and used portions through several venues, including as collateral in Aave markets. Aave reported that its own smart contracts were not compromised. It also described the situation as evolving and warned that its assessment could change as KelpDAO, LayerZero and other parties supplied more information.
Arbitrum said its Security Council acted with input from law enforcement concerning the exploiter’s identity. That was an attributable contemporaneous claim, not a publicly documented court finding in the April 21 record. The cited evidence also did not establish the ultimate ownership or distribution of the frozen ether.
A recovery with a governance cost
The action mattered because it immobilized a substantial pool of ether before it could leave Arbitrum One, while exposing the practical reach of emergency upgrade authority. A small designated body could intervene faster than a full token-holder vote, but the method also showed that core-contract control could override the normal requirement that an account authorize its own transfer.
That tradeoff is central to evaluating layer-2 networks. Ethereum supplied the settlement layer and the transaction record, but Arbitrum’s upgrade mechanism determined what could happen inside the rollup during an emergency. The episode therefore concerned more than exploit recovery: it made the network’s governance assumptions visible in a single transaction.
As of April 21, 2026, the verified outcome was limited. The ether had been moved to the intermediary address, and the original address could no longer spend it. No cited event-day record established that affected users had been repaid, that the wider rsETH deficit had been resolved or that governance had approved a final destination for the funds.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

