18 April 2026
An attacker sent a crafted message to Kelp's LayerZero cross-chain adapter and minted 116,500 rsETH out of nothing — roughly $292m, about 18% of supply, and the largest DeFi loss of the year. DPRK-linked actors were credited with it. The restaking contracts were never breached; the verification configuration around the bridge was, and it turned out to be a single point of failure that no documentation had surfaced as one.
Why the damage did not stop there
The minted rsETH was posted as collateral on Aave and borrowed against, which pushed between $177m and $236m of bad debt onto a lending protocol that had done nothing wrong except list the token. This is the clearest illustration the sector has produced that a wrapped asset carries its weakest link into every market that accepts it.
What is left
A published post-mortem naming the cause, operator delegations still visible on-chain, and a backing question that has to be resolved before the token means anything again. Redemption was overwhelmed by unbacked supply.
Our position
There is no case for a new deposit here until the backing is restored and the cross-chain design is replaced with something that does not depend on one verification path.