KelpDAO's $175M Laundering Spree: THORChain Weaponized, Arbitrum Draws a Historic Line in the Sand

Three days after stealing $292M in rsETH, suspected North Korean hackers began a cross-chain laundering operation that spiked THORChain's daily volume 10x β€” until Arbitrum's Security Council staged the most aggressive real-time governance intervention in DeFi history.

Executive Summary

  • Hackers moved 75,701 ETH ($175M) to three freshly-created wallets on April 21, routing at least 34,500 ETH ($80M) through THORChain to convert into Bitcoin β€” spiking the protocol's 24-hour volume to ~$360M and fee revenue to ~$420,000 in a single day

  • The Arbitrum Security Council froze 30,766 ETH (~$71.5M) in a landmark emergency action, citing law enforcement coordination and voting 9-of-12 in favor β€” the most significant Layer-2 governance intervention against a live exploit on record

  • AAVE suffered cascading bad debt estimated at $123M–$230M as attackers weaponized stolen rsETH as DeFi collateral, driving $13.2B in total DeFi TVL losses across 48 hours

  • LayerZero and Kelp DAO are engaged in a public blame war over who bears responsibility for the single-verifier (1-of-1 DVN) configuration that enabled the exploit, with North Korea's Lazarus Group / TraderTraitor unit named as the likely perpetrator

  • The laundering operation is still in its early stages; roughly $45M in ETH remains unaccounted for across the attacker's three wallets, and cross-chain conversion to Bitcoin will make further recovery increasingly difficult


Background & Market Context

Our April 19 report covered the initial mechanics of the KelpDAO exploit: on April 18, 2026, attackers drained 116,500 rsETH (approximately $292 million) from Kelp's LayerZero-powered Omnichain Fungible Token (OFT) bridge by manipulating the protocol's Decentralized Verified Network (DVN) β€” poisoning two RPC nodes while DDoS-attacking a third, then submitting a fraudulent cross-chain message (nonce 308) that tricked the bridge into releasing real rsETH without a corresponding burn on the source chain. An emergency pause 46 minutes after the attack blocked additional attempts that would have added another ~$200M to the haul. What was unclear on April 19 was how the attacker would move the funds, how other DeFi protocols would absorb the shock, and whether any on-chain governance body would attempt real-time intervention.

The developments of April 20–22 answer all three questions decisively β€” and the answers have major implications for institutional DeFi risk frameworks, Layer-2 governance design, and the ongoing regulatory debate around permissionless cross-chain protocols like THORChain. The laundering operation that has now begun follows a sophisticated multi-hop architecture: consolidate on mainnet, fragment into smaller tranches, bridge to Bitcoin through decentralized, KYC-free channels, and exit via over-the-counter desks. This is a playbook the Lazarus Group has used in at least a dozen major exploits, including the $625M Ronin Bridge hack (2022) and the $100M Horizon Bridge theft (2022).

What makes the KelpDAO case structurally different is the sheer size of the haul relative to the liquidity available in decentralized laundering channels. $175M in ETH is not easily absorbed even by THORChain's deep liquidity pools β€” and the volume spike that resulted became one of the most visible signals of illicit activity a DeFi protocol has ever emitted in real time. Meanwhile, Arbitrum's Security Council demonstrated that Layer-2 governance structures can, under the right conditions, act faster than a sophisticated state-sponsored attacker. Whether that speed is welcome depends entirely on your views about decentralization.

The macro backdrop matters: 2026 has already seen $1.4B in DeFi exploits through April β€” on pace to exceed 2022's $3.8B record. Restaking protocols specifically have become the most attractive attack surface because they aggregate collateral across multiple chains under a single bridge trust assumption. KelpDAO's rsETH was accepted as collateral by at least four major lending markets (AAVE, SparkLend, Fluid, Morpho) across more than 20 networks β€” meaning a single bridge failure could simultaneously impair every downstream venue. That is precisely what happened.


Key Developments

April 18, 2026 β€” The Initial Exploit At approximately 14:32 UTC, an attacker pre-funded via Tornado Cash executes fraudulent LayerZero message nonce 308, triggering the release of 116,500 rsETH (~$292M) from Kelp's OFT bridge adapter. An emergency pause is activated 46 minutes later, blocking two follow-up attempts that would have drained an additional $200M. The attacker's primary wallet begins receiving funds at 0xKelpExploiter (Arkham-tagged address). The rsETH price depeg begins immediately on secondary markets, triggering cascading liquidations on AAVE.

April 19, 2026 β€” DeFi Contagion Spreads AAVE's rsETH-wETH markets on Ethereum mainnet reach peak stress as the attacker is identified as having dumped stolen tokens on AAVE V3 as collateral and borrowed wrapped ETH against them. AAVE's total TVL falls from $26.4B to ~$20B β€” a $6.4B single-day drop. All of AAVE's core markets hit 100% utilization simultaneously, effectively freezing approximately $5B in USDT and USDC withdrawals. LayerZero releases a post-mortem attributing the attack to North Korea's Lazarus Group / TraderTraitor unit, simultaneously deflecting blame toward Kelp DAO's single-verifier configuration. Kelp DAO counters that the 1-of-1 DVN setup followed LayerZero's documented defaults.

April 20, 2026 β€” Arbitrum Security Council Acts The Arbitrum Security Council votes 9-of-12 to execute Emergency Action on the exploiter's Arbitrum One holdings. The council freezes 30,765.667 ETH β€” valued at approximately $71.5M β€” moving the assets to intermediary address 0x0000000000000000000000000000000000000DA0, inaccessible to the original exploiter. The council states it acted with "input from law enforcement as to the exploiter's identity" and that it "did not make this decision lightly." The action triggers an immediate debate about Layer-2 decentralization, with critics arguing it demonstrates that L2s retain a master-key override capability that contradicts their permissionless marketing.

April 21, 2026 β€” The $175M Move Arkham Intelligence flags three large transactions from the primary Kelp exploiter wallet: 25,000 ETH to 0xF9802c5EB6b972Ba686aFa7CA615910Ea8310b85, 50,700 ETH to 0xD4B87bAB0ee142182f7F6DA030AeFe3E7f171530, and 0.7 ETH to 0x62c72510016732333e68177d388a8111643FC64E. Total moved: 75,701 ETH (~$175.4M). This represents the funds the attacker retained after the Arbitrum freeze β€” approximately 60% of the original haul.

April 21–22, 2026 β€” THORChain Routing Begins ZachXBT flags three initial THORChain transactions totaling $1.5M (ETHβ†’BTC). A second wave, confirmed by PeckShield and Bloomingbit, shows 34,500 ETH ($80M) being systematically routed through THORChain to Bitcoin in tranches, with additional flows through Umbra ($78K), Chainflip, and BitTorrent Chain. THORChain's 24-hour volume surges to approximately $360M β€” more than 10x its normal baseline β€” and fee revenue reaches ~$420,000 in a single day. The conversion to Bitcoin is critical: once assets cross into the Bitcoin network via THORChain's decentralized liquidity pools, recovery through DeFi governance mechanisms like Arbitrum's becomes technically impossible.


Technical Analysis

The Laundering Architecture: A Multi-Stage Obfuscation Pipeline

The KelpDAO attacker is executing a classic North Korean state-sponsored laundering sequence, adapted for 2026's DeFi infrastructure. Stage one β€” consolidation β€” was executed on April 21 when 75,701 ETH was swept from the primary exploit wallet into three fresh, uncontaminated addresses. This is standard operational security: severing the direct link between the exploit address (which is now blacklisted by centralized exchanges and flagged by Chainalysis/Arkham) and the wallets that will conduct the actual laundering. Each of the three destination wallets received distinct round-number allocations, suggesting they are designated for different laundering channels or time windows.

Stage two β€” cross-chain conversion β€” is already underway via THORChain. THORChain is uniquely attractive for this purpose: it is a truly decentralized, non-custodial cross-chain swap protocol that enforces no KYC, maintains no block list, and has historically resisted pressure to freeze or censor transactions. ETH-to-BTC swaps via THORChain require only on-chain liquidity, and with $360M+ in 24-hour volume, the attacker's tranches of $2-5M are effectively camouflaged within ordinary trading flow. THORChain's architecture routes swaps through RUNE as an intermediary asset, meaning the laundering footprint is: ETH β†’ RUNE β†’ BTC. Each hop introduces additional analytical complexity.

Why Bitcoin Is the Destination

Bitcoin's UTXO model, combined with CoinJoin protocols (Wasabi Wallet, JoinMarket) and decentralized OTC desks, provides superior long-term obfuscation compared to Ethereum's account-based system. The Lazarus Group's standard playbook after cross-chain conversion to BTC involves: (1) automated UTXO mixing over 6–12 months; (2) peer-to-peer exchange via platforms like Bisq that lack KYC; (3) final conversion to fiat via compliant OTC desks in jurisdictions with weak AML enforcement, particularly Southeast Asia and the UAE. OFAC has sanctioned multiple THORChain-connected mixer addresses in past Lazarus operations, but THORChain's protocol layer cannot enforce these sanctions β€” only the frontend interface can block sanctioned addresses, and the attacker is almost certainly interacting directly with smart contracts.

The rsETH Bridge Vulnerability Revisited

The root cause is worth revisiting in the context of the laundering response: LayerZero's OFT bridge used a 1-of-1 DVN (a single verifier node cluster) to confirm cross-chain messages for KelpDAO's rsETH. A 1-of-1 setup means that if a single DVN is compromised, the entire bridge can be fooled. LayerZero's default configuration for new deployments allows this setup β€” Kelp accepted it. The attacker bypassed LayerZero's monitoring by selectively lying: the compromised nodes reported fraudulent transactions only to LayerZero's DVN, while delivering accurate data to all other querying systems, making the attack invisible to standard monitoring dashboards.

The 46-minute detection window is concerning. For a $292M drain, institutional security teams would expect sub-5-minute automated circuit breakers. The gap suggests that KelpDAO's anomaly detection system either (a) did not have real-time oracle price monitoring that would flag a 18%-of-supply drain, or (b) had manual review steps in its incident response pipeline that introduced fatal latency.

flowchart TD
    A["Attacker\n(Lazarus / TraderTraitor)"] -->|"Pre-fund via Tornado Cash"| B["Exploit Wallet\n0xKelpExploiter"]
    B -->|"Fraudulent DVN message\n(nonce 308)"| C["LayerZero OFT Bridge\n1-of-1 DVN Config"]
    C -->|"Releases 116,500 rsETH\n~$292M"| D["Attacker Receives rsETH"]
    D -->|"Dump as collateral"| E["AAVE V3\n$196M bad debt"]
    D -->|"Remaining ETH\n~$120M"| F["Arbitrum Holdings\n30,766 ETH"]
    F -->|"Emergency Action\n9/12 Council vote"| G["Frozen by Arbitrum\nSecurity Council\n$71.5M"]
    D -->|"Bridge to mainnet\n75,701 ETH"| H["3 Fresh Wallets\n~$175M"]
    H -->|"25,000 ETH"| I["Wallet 0xF980..."]
    H -->|"50,700 ETH"| J["Wallet 0xD4B8..."]
    I & J -->|"THORChain\nETH→RUNE→BTC"| K["Bitcoin\n~$80M converted"]
    I & J -->|"Umbra / Chainflip"| L["Privacy Protocols\n~$1.6M+ routed"]
    K -->|"UTXO mixing\nOTC desks"| M["Final fiat exit\n(6-12 months)"]
    style G fill:#ff4444,color:#fff
    style M fill:#888,color:#fff
    style K fill:#f7931a,color:#fff

On-Chain & Market Data

Metric

Value

Change

Source

Total KelpDAO exploit value

$292M (116,500 rsETH)

N/A (initial)

CoinDesk / LayerZero post-mortem

ETH moved to fresh wallets (Apr 21)

75,701 ETH (~$175M)

β€”

Arkham Intelligence

ETH frozen by Arbitrum Security Council

30,766 ETH (~$71.5M)

β€”

Arbitrum Foundation

ETH routed via THORChain (confirmed)

34,500 ETH (~$80M)

β€”

PeckShield / Bloomingbit

THORChain 24h volume (peak)

~$360M

+1,000%+ vs baseline

Crypto.news / Bloomingbit

THORChain 24h fee revenue (peak)

~$420,000

+1,000%+ vs baseline

Bloomingbit

AAVE bad debt (Eth mainnet, rsETH-wETH)

$123M–$230M

β€”

LlamaRisk / CoinDesk

AAVE TVL drop (48 hours)

$6.4B+ ($26.4B β†’ ~$20B)

-24%

CoinDesk

Total DeFi TVL loss (48 hours)

$13.21B

-~8% DeFi-wide

CoinDesk Markets

rsETH circulating supply drained

18%

β€”

KelpDAO post-mortem

Umbra privacy routing

$78,000

β€”

ZachXBT / Telegram

AAVE USDT/USDC frozen (100% util.)

~$5B

0% withdrawable

CoinDesk

The THORChain data is perhaps the most striking signal of all. A 10x spike in daily volume to $360M on a protocol whose normal activity sits below $35M/day is not statistical noise β€” it is a searchlight. For context, THORChain's best recent quarters showed daily averages of roughly $50-80M. The laundering inflows from KelpDAO represent approximately 30% of total protocol-level liquidity being churned in a single 24-hour period, compressing pool slippage and generating $420K in fee revenue that accrues to RUNE liquidity providers β€” an ironic subsidy from stolen funds to legitimate yield farmers.

The AAVE data reveals a separate crisis layer. The $123M–$230M bad debt range persists because of a methodological dispute: if rsETH losses are distributed pro-rata across all rsETH holders, the Ethereum mainnet Aave market absorbs ~$123M. If the shortfall is allocated only to Layer 2 venues where the attacker's rsETH was concentrated, that figure rises to $230M. Aave's Safety Module (AAVE stakers) is the backstop for bad debt above a certain threshold β€” meaning AAVE token holders face a potential socialized loss event even after the exploit itself has been well-publicized.

KelpDAO Hacker Moving Funds: Attacker Transfers $175M to New Addresses


Competitive Landscape

KelpDAO vs. Peer Restaking Protocols

The KelpDAO exploit occurred in a market where liquid restaking protocols (LRTs) have become DeFi's second-largest asset category by TVL after stablecoins. The comparison with competitors is critical for assessing relative risk:

EigenLayer (the base restaking layer for most LRTs) escaped direct exposure because the attack targeted Kelp's LayerZero bridge rather than the EigenLayer AVS layer itself. However, EigenLayer's TVL β€” over $12B at the time of the exploit β€” is distributed across dozens of operator sets with similar bridge dependencies. The KelpDAO hack demonstrated that any LRT deploying assets to a LayerZero OFT bridge with a 1-of-1 DVN configuration faces the same attack surface. EigenLayer released a statement noting that its protocol architecture was not directly implicated, but market confidence in the broader restaking category fell sharply regardless.

Ether.fi's eETH and Renzo's ezETH both saw temporary depegs of 0.3–0.8% as contagion sentiment spread, despite having no technical exposure to the KelpDAO bridge. This "guilt by association" repricing is characteristic of DeFi crises and reflects the difficulty retail investors have distinguishing between correlated risk and identical risk. Ether.fi's security architecture differs from KelpDAO in one key respect: it uses multi-verifier DVN configurations on cross-chain bridges, the redundancy that KelpDAO lacked. This detail became an important marketing differentiator within 48 hours of the exploit.

Pendle Finance, which had structured yield positions against rsETH, faced the most unusual secondary exposure: Pendle's PT-rsETH tokens (principal tokens with fixed-maturity yields) theoretically depend on rsETH's eventual redemption at par. With rsETH permanently impaired, PT-rsETH holders face losses calibrated to the final recovery rate β€” estimated at 60–70 cents on the dollar depending on AAVE's bad debt resolution process.

THORChain occupies an uncomfortable position in the competitive landscape: it is simultaneously a victim (its reputation as a neutral liquidity layer is damaged by being the primary laundering rail), a beneficiary (fee revenue spiked dramatically), and an object of regulatory scrutiny. THORChain's prior brush with sanctions came in 2022 when OFAC flagged several of its liquidity pools for Tornado Cash-adjacent activity. The KelpDAO laundering event will intensify calls for THORChain to implement optional address screening β€” calls its developer community has historically rejected on ideological grounds.


Stakeholder Analysis

Retail KelpDAO Depositors Approximately 82% of the original rsETH supply (those not captured in the exploit) remains in the hands of legitimate depositors across 20+ chains. Their recovery rate depends entirely on KelpDAO's ability to (a) negotiate the return or reallocation of the $71.5M Arbitrum-frozen ETH through governance, and (b) absorb or socialize the AAVE bad debt exposure. Current estimates suggest depositors face a 20–35% haircut on their original deposits. No compensation fund or insurance mechanism was in place pre-exploit.

AAVE Stakers and Governance AAVE's Safety Module β€” funded by staked AAVE tokens β€” is the protocol's last line of defense against bad debt. A $196M bad debt event could trigger a governance vote to slash Safety Module participants, distributing losses across AAVE stakers who had no direct exposure to rsETH. Dragonfly Capital's public analysis characterized the AAVE situation as "serious but not structural" β€” arguing AAVE's diversified collateral mix prevents a solvency crisis even at the high end of bad debt estimates. However, with all core markets at 100% utilization and $5B in USDT/USDC withdrawals effectively frozen, even a temporary liquidity seizure constitutes a material user harm.

Arbitrum Governance Participants and ARB Token Holders The Security Council's freeze creates a novel governance problem: the 30,766 ETH cannot be returned to KelpDAO depositors without a full Arbitrum governance vote β€” a process that takes weeks under standard DAO procedures. This means that even "recovered" funds will be tied up in governance limbo during a period when the hacker is actively converting the remaining $175M to Bitcoin. ARB token holders, as governance participants, now face a vote with significant legal and political dimensions: returning funds to a hack victim is popular; setting a precedent for arbitrary asset freezes is not.

LayerZero Protocol and ZRO Token Holders LayerZero's ZRO token has fallen sharply in the post-exploit period as the blame war with KelpDAO damages the protocol's reputation as critical infrastructure. If it is ultimately determined β€” through litigation or DAO governance β€” that LayerZero's documented default settings enabled the exploit, the protocol faces potential liability and a significant security review burden. Multiple major DeFi protocols that use LayerZero bridges have quietly begun auditing their DVN configurations. A wave of migrations to multi-verifier setups would reduce LayerZero's short-term fee revenue from bridge activity.

Regulators and Law Enforcement The Arbitrum Security Council explicitly cited law enforcement input in its freeze action β€” the first documented instance of a DeFi Layer-2 governance body coordinating with law enforcement agencies in real time. This creates a precedent that regulators will note: DeFi governance bodies can act as de facto financial intermediaries when incentivized or pressured to do so. OFAC and FinCEN will likely use this case to argue that L2 governance structures meet the definition of "control" over user funds β€” a finding with sweeping implications for how L2s are regulated under the Bank Secrecy Act and emerging crypto asset frameworks in the EU (MiCA) and UK (FSMA).


Risk Assessment

  1. Full Conversion to Bitcoin Before Recovery β€” Critical Severity, High Probability β€” The attacker has already converted approximately $80M of the $175M to Bitcoin via THORChain. Once in Bitcoin's UTXO system, the probability of recovery falls below 5% based on historical Lazarus Group operations. Remaining ETH (~$95M across three wallets) is still theoretically intercept-able through exchange cooperation, but the attacker's operational pace β€” moving $80M within 48 hours β€” suggests the window is narrow. If current routing rates continue, the entire $175M could be in Bitcoin within 7–10 days.

  2. AAVE Safety Module Slashing Event β€” High Severity, Medium Probability β€” If the AAVE community votes to activate the Safety Module to cover bad debt, AAVE stakers face a proportional loss. The $196M bad debt figure represents approximately 15% of the Safety Module's collateral at current AAVE prices. A slashing event would likely trigger a secondary selloff in AAVE tokens, creating a reflexive loop. Dragonfly's "not structural" assessment provides some comfort, but 100% utilization persisting beyond 48–72 hours would force governance action.

  3. Regulatory Action Against THORChain β€” Medium Severity, Medium Probability β€” The US Treasury / OFAC have sanctioned DeFi protocols before (Tornado Cash, 2022). THORChain's role as the primary laundering rail for the largest DeFi exploit of 2026 provides significant political impetus for another designation. If THORChain's frontend domains or the Thornode operators (many of whom are publicly known) are sanctioned, RUNE token liquidity could collapse. The counterargument is that THORChain's truly decentralized node structure makes enforcement technically incomplete β€” Tornado Cash's sanction is still contested in court.

  4. L2 Governance Centralization Risk Crystallization β€” Medium Severity, High Probability β€” The Arbitrum Security Council action, while pragmatically beneficial, has materially damaged the "trust minimized" narrative for Layer-2 networks broadly. If the 9-of-12 council vote is perceived as a slippery slope toward governance censorship, institutional depositors who chose L2s specifically for their permissionless guarantees may reduce exposure. Competing L2s (Optimism, Base, zkSync) will face similar scrutiny of their own security council configurations.

Kelp DAO exploit fallout deepens as attacker routes $175M in ETH via privacy rails


Investment & Strategic Implications

For hedge funds and institutional DeFi allocators, the KelpDAO incident delivers a clear portfolio construction message: correlated collateral risk in restaking protocols is not currently priced correctly. Before this exploit, rsETH's deployment across 20+ networks and acceptance by four major lending markets was viewed as a feature β€” broad integration signals protocol maturity and utility. Post-exploit, it is clearly a liability: a single bridge failure simultaneously impairs every downstream venue in a way that no diversified portfolio of DeFi lending positions can absorb. Institutional risk managers should immediately audit all LRT positions for cross-chain bridge architecture β€” specifically, whether the bridge's DVN configuration uses 1-of-1 or redundant multi-verifier setups. Protocols using LayerZero OFT bridges with single-verifier configurations should be placed on watch or reduced until an architecture upgrade is confirmed.

For DeFi protocol builders, the incident makes a compelling case for a "defense in depth" approach to bridge security: multi-verifier DVN configurations as an absolute minimum, automated circuit breakers calibrated to supply-side anomalies (an 18%-of-supply drain should trigger automatic pause within seconds, not 46 minutes), and real-time oracle discrepancy monitoring between collateral markets and bridge balances. KelpDAO's architecture assumed that LayerZero's infrastructure was the trust anchor β€” a reasonable assumption until it wasn't. The lesson is that any single trust anchor in a $300M+ system represents unacceptable concentration risk.

For governance token holders in L2s like Arbitrum, Optimism, and Base, the Security Council's action creates a precedent that governance participants must now formalize rather than leave ad hoc. Does the council have explicit authority to freeze funds based on law enforcement input? Under what circumstances? With what transparency requirements and appeal mechanisms? The absence of a formal framework means each future use of this power will generate the same decentralization debate, eroding community trust incrementally. Proactive governance frameworks for emergency powers β€” clearly scoped, time-limited, and subject to community ratification β€” would reduce this friction significantly and may become a competitive differentiator for institutional capital seeking "responsible decentralization."


Outlook: 30 / 180 / 365 Days

  • 30 days: The remaining ~$95M in ETH across the attacker's three wallets will either complete conversion to Bitcoin (most probable) or see a portion frozen through additional exchange cooperation and law enforcement coordination. KelpDAO will publish a recovery plan with an rsETH haircut ratio; AAVE governance will vote on Safety Module activation; the LayerZero-Kelp DAO blame war will escalate to formal arbitration or litigation. ZRO and AAVE tokens face continued selling pressure. The Arbitrum frozen ETH ($71.5M) will remain in governance limbo pending a formal DAO vote, which will not complete within 30 days.

  • 180 days: If OFAC sanctions THORChain-related addresses (as it did with Tornado Cash), RUNE will reprice dramatically and THORChain's legitimate trading volume will migrate to alternatives (Chainflip, Maya Protocol). A formal multi-agency law enforcement action against identified Lazarus Group operatives is possible but unlikely to result in fund recovery. The broader LRT sector will consolidate around 2–3 protocols with demonstrably superior bridge security architectures; protocols that have not upgraded from 1-of-1 DVN configurations by mid-2026 will face institutional outflows. AAVE will resolve its bad debt situation through a combination of Safety Module backstop and a negotiated rsETH recovery distribution.

  • 365 days: The KelpDAO hack will become the canonical case study for LRT bridge risk and L2 governance intervention, cited in regulatory proposals across multiple jurisdictions as evidence that DeFi requires minimum security standards for bridge verification architecture. The recovery rate for KelpDAO depositors will depend on the eventual disposition of Arbitrum's frozen $71.5M β€” the most likely outcome is a community vote to return these funds to a KelpDAO recovery pool, partially offsetting losses for depositors. Lazarus Group's laundering will have succeeded in converting the majority of the $175M to Bitcoin and fiat, following the pattern of every prior major DPRK crypto theft. No meaningful recovery of the laundered portion will occur. The incident will accelerate the adoption of mandatory multi-verifier bridge standards and on-chain proof-of-reserve requirements for LRT collateral in major lending markets.


References

  1. KelpDAO Hacker Moving Funds: Attacker Transfers $175M to New Addresses β€” Arkham Intelligence

  2. The KelpDAO Thieves Just Moved $175 Million as the Laundering Process Begins β€” CoinDesk

  3. Kelp DAO Exploiter Begins Moving Stolen Funds Across Chains After Arbitrum ETH Freeze β€” The Block

  4. Arbitrum Security Council Freezes $71.5M in Ethereum Linked to $292M KelpDAO Exploit β€” Decrypt

  5. ETH News: Arbitrum Freezes $71 Million in Ether Tied to Kelp DAO Exploit β€” CoinDesk

  6. Arbitrum Takes Back $71M From Kelp DAO Hacker: 'We Did Not Make This Decision Lightly' β€” DL News

  7. Kelp Exploiter Launders $175M in Stolen Funds via THORChain, Umbra β€” Blockchain.news

  8. KelpDAO Hacker Launders 34,500 ETH, Sending THORChain Volume Surging β€” Bloomingbit

  9. Kelp DAO Exploit: Hacker's $80M ETH to Bitcoin Swap Triggers THORChain Volume Frenzy β€” Bitcoinworld

  10. LayerZero Blames Kelp's Setup for $290 Million Exploit, Attributes It to North Korea's Lazarus β€” CoinDesk

  11. Kelp DAO Claims LayerZero's Default Settings Caused the $290 Million Disaster β€” CoinDesk

  12. Aave Could Face Up to $230 Million in Losses After Kelp DAO Bridge Exploit β€” CoinDesk

  13. Aave's Core Markets Hit 100% Utilization β€” CoinDesk

  14. DeFi TVL Drops More Than $13 Billion in Two Days Following Kelp DAO Hack β€” CoinDesk

  15. Kelp DAO Exploit Fallout Deepens as Attacker Routes $175M Via Privacy Rails β€” Crypto.news

  16. Security Council Emergency Action – 21/04/2026 β€” Arbitrum Forum

  17. LayerZero Says North Korea's Lazarus Likely Behind Kelp DAO Exploit β€” The Block

  18. Hackers Behind $300 Million Crypto Theft Now Laundering Loot β€” Bloomberg

  19. KelpDAO Exploiter Moves 75,701 ETH to Mainnet, Begins Routing $175M to Bitcoin β€” Bitcoin.com News

  20. Incident Report: Llamarisk, Aave Service Providers Detail Kelp rsETH Hack β€” Bitcoin.com News