Kelp DAO’s cross-chain rsETH route released 116,500 rsETH to an attacker-controlled address on April 18, 2026, after a LayerZero message was accepted without a corresponding token burn on the source chain. The successful Ethereum transaction occurred at 17:35 UTC. Event-day reporting described the tokens as worth approximately $292 million, making the incident a major test of bridge verification and of the lending markets that accepted rsETH as collateral.
The dollar figure was a contemporaneous estimate, not an official close. The Block published it at 3:18 p.m. EDT and updated the report at 4:40 p.m. EDT, citing “current market prices” and later noting rsETH near $2,500. It did not specify an exchange, benchmark or exact valuation tick. The verified quantity is therefore 116,500 rsETH; approximately $292 million is useful only as an event-day indication of scale.
What was known on April 18
Transaction logs reviewed that day showed a call through LayerZero’s EndpointV2 contract caused Kelp’s Ethereum-side bridge contract to release the rsETH. At 18:21 UTC, 46 minutes after the successful drain, Kelp’s emergency pauser multisig paused core contracts. Two further transactions at 18:26 UTC and 18:28 UTC reverted. Kelp publicly acknowledged suspicious cross-chain activity at 20:10 UTC and said it was investigating with LayerZero, Unichain, auditors and security specialists.
Aave’s response showed why the event extended beyond one bridge. Beginning at 18:52 UTC, its Guardian froze rsETH and wrapped rsETH markets across deployments where the assets were listed. The restriction stopped new deposits and new borrowing against the affected collateral while leaving existing positions unchanged by the freeze itself. Aave said its pools remained operational and that the suspected exploit did not originate in Aave’s own contracts.
Those facts established containment, not a final loss. Kelp had not published a root-cause report, Aave had not completed a deficit calculation, and no public event-day record established who controlled the attacker addresses. Claims about recovery, ultimate creditor losses or state sponsorship were unresolved on April 18.
Why one message mattered
Cross-chain token systems depend on an invariant: assets released or represented on one chain must correspond to assets locked or burned on another. A destination contract can execute exactly as programmed and still produce an unauthorized result if it receives a false but validly attested message.
That distinction made the incident institutionally important. The failure was not framed as a break in Ethereum consensus or in the rsETH token’s basic transfer logic. It concerned the verification path connecting chains. Once the released rsETH moved into lending venues, bridge assurance became collateral risk for protocols and depositors that had not operated the bridge themselves.
Aave’s rapid freezes also illustrated the limits of emergency governance. Guardians could stop additional deposits and borrows, but they could not reverse transfers already confirmed or immediately determine how any shortfall would be allocated. The episode linked bridge configuration, off-chain infrastructure, collateral policy and multichain incident response in a single event.
Later confirmation, kept separate
On April 19, LayerZero said the affected rsETH application used its LayerZero Labs Decentralized Verifier Network as the sole verifier in a one-of-one configuration. LayerZero attributed the false attestation to poisoned RPC infrastructure combined with denial-of-service pressure against uncompromised RPCs. That was an involved provider’s preliminary account, not information available when the drain first appeared on April 18.
Aave service providers’ April 20 report later confirmed Ethereum block 24,908,285, the 17:35 UTC time, the 116,500-rsETH release and the absence of a corresponding Unichain burn. Those later records strengthen the central claim but do not change the event-day boundary: on April 18, the exploit, emergency pauses and immediate lending-market response were verified, while root cause, attribution, recoveries and final losses remained open.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

