Press play to start listening
A forged cross-chain message released 116,500 rsETH, worth about $292 million, from KelpDAO’s Ethereum bridge on April 18, 2026. The attacker then deposited much of the unbacked token into Aave, Compound and Euler, borrowing real assets against collateral that the bridge should never have released.
Bitcoin was outside every part of the incident. KelpDAO, rsETH, and the affected LayerZero bridge operate within the Ethereum ecosystem, whereas Bitcoin operates under its own consensus rules and transaction model. Its network targets an average block interval of about ten minutes, although individual blocks can arrive sooner or later.
How the Forged Message Released $292 Million
At 17:35 UTC, the KelpDAO bridge accepted a message claiming that rsETH had been burned on Unichain. No burn had occurred, but a single LayerZero Decentralized Verifier Network had approved the message. With no second independent verifier required, the Ethereum contract released 116,500 rsETH to the attacker, according to Aave’s incident report.
LayerZero’s final investigation found that the operation began on March 6, when an attacker socially engineered a developer and obtained session keys. The attacker entered LayerZero’s RPC cloud environment, altered two internal RPC nodes, and disrupted an external provider. The verifier was then given false source-chain data while LayerZero’s monitoring systems received legitimate responses.
KelpDAO paused its main contracts 46 minutes after the successful drain. Two subsequent attempts to release another 40,000 rsETH failed because the recipient had been frozen and funds had been recovered from the bridge adapter.
Cyvers co-founder and CTO Meir Dolev said KelpDAO had been “just three minutes away from losing an additional $100 million,” before the blacklist blocked the second attempt. The statement appeared in a Cyvers post on X. A later Chainalysis analysis valued the blocked 40,000 rsETH withdrawal at about $95 million.
How the Bridge Failure Reached Lending Protocols
Once the attacker controlled the rsETH, it could be deposited as collateral elsewhere. Galaxy Research identified positions on Aave, Compound and Euler, with an estimated $236 million borrowed in WETH and wstETH.
Aave received most of the stolen collateral. Its report recorded 89,567 rsETH deposited into its markets, followed by loans of approximately 82,650 WETH and 821 wstETH. Aave’s contracts were not breached, but they processed the rsETH as valid collateral because the bridge transaction had passed its required verification.
Aave began freezing rsETH and wrsETH markets at 18:52 UTC, 77 minutes after the drain. Other projects, including SparkLend, Fluid, Upshift, Lido, Pendle and Yearn, paused affected markets or products. These actions do not mean nine independent lending venues were compromised. Only three lenders were identified as direct destinations for the attacker’s collateral.
During the following 48 hours, Galaxy measured a decline in DeFi total value locked from about $99.5 billion to $86.3 billion, a reduction of approximately $13.2 billion. DL News later reported a decline exceeding $15 billion, using a later DefiLlama snapshot. TVL changes can reflect withdrawals and falling asset prices, so the figure should not be described entirely as capital leaving the sector.
The reported 20 percent token decline also needs attribution. It was Aave’s AAVE token, not rsETH, that CoinGecko reported down 17.9 percent following the incident.
Why Bitcoin Was Not Exposed
Bitcoin’s base layer does not accept cross-chain release messages or use external collateral records. Under its UTXO model, every transaction input must reference an unspent output, and each output can be spent only once, as explained in the Bitcoin developer documentation.
A valid Bitcoin transaction must also satisfy the conditions in the output’s locking script. This differs from saying every Bitcoin transfer requires a conventional signature, since Bitcoin Script supports other spending conditions.
The distinction does not make every Bitcoin-related product immune. Wrapped Bitcoin, custodial services, exchanges, sidechains and lending products can introduce verifiers, administrators and other dependencies outside Bitcoin’s base layer.
Bitcoin’s market price was not literally motionless. It fluctuated during the period and rebounded above $76,000 on April 20. The accurate claim is that the KelpDAO exploit did not interrupt Bitcoin’s network or alter its consensus process.
For a later market reference, Binance’s Bitcoin to USD rate listed BTC at $63,877.08 on August 3 at 20:39 UTC, with a market capitalization of $1.3 trillion and 20.1 million coins circulating. That timestamped snapshot should not be presented as a July 31 closing price.
Where the CLARITY Act Fits
The Senate Banking Committee advanced the CLARITY Act by a 15-to-9 vote in May. Senators released updated combined text on July 22, but the bill had not passed the full Senate at the time of writing.
The proposal covers digital commodities, securities, intermediaries, anti-money-laundering duties, decentralized finance and tokenized securities. It is not a simple table assigning every asset to either the SEC or CFTC, and it would not stop a compromised RPC node from supplying false information to a bridge.
Bitcoin is already treated as a commodity under the Commodity Exchange Act, according to the CFTC (PDF). The bill would still affect exchanges, brokers and other intermediaries handling Bitcoin.
Binance co-CEO Richard Teng discussed rebuilding financial services with modern infrastructure during a June 30 Figuring Out podcast. His comments concerned financial architecture generally and were not a response to the KelpDAO attack.
Five Facts Established by the Incident
- One verifier was enough to authorize the forged bridge message.
- The attacker used three identified lending protocols, not nine compromised lenders.
- The blacklist stopped a second 40,000 rsETH release but could not reverse the first transaction.
- DeFi TVL fell by about $13.2 billion within 48 hours, while later estimates exceeded $15 billion.
- Bitcoin’s base network was unaffected, but Bitcoin services using bridges or custodians can carry separate risks.
What Comes Next
Bitcoin’s nearest difficulty adjustment occurred on April 17, one day before the KelpDAO attack, not two days afterward. Difficulty fell 2.43 percent to 135.59 trillion at block 945,504, according to Newhedge’s adjustment history. The next adjustment occurred on May 2. Neither event had any connection to KelpDAO.
Bitcoin records UTXOs in its public ledger, while block explorers are third-party tools that index and display those records. This transparency helps trace transactions, but it does not remove the need to review wallets, custody systems, scripts, bridges, and applications built around Bitcoin.
(Photo by André François McKenzie on Unsplash)