Kelp Hit by Major Bridge Exploit, Triggering Ripple Effects Across DeFi Platforms

Liquid restaking platform Kelp has become the latest victim of a large-scale cyberattack after suspicious activity involving its rsETH token led to an emergency shutdown of smart contracts across Ethereum mainnet and several Layer-2 networks.

The incident began on Saturday when Kelp detected abnormal cross-chain transactions tied to rsETH, prompting the protocol to suspend related contracts while an internal investigation continues.

According to blockchain security firm Cyvers, the breach stemmed from the exploitation of Kelp’s rsETH adapter bridge contract — a critical component used to manage token transfers across networks. Attackers allegedly siphoned nearly $293 million in digital assets during the exploit.

Cyvers further reported that the stolen funds were moved through an address initially funded via Tornado Cash, a crypto mixer often linked to laundering activity. Roughly $250 million of the stolen assets have already been converted into Ether (ETH), making recovery efforts more difficult.

The fallout quickly spread beyond Kelp. DeFi lending giant Aave responded by freezing rsETH-related markets on both its V3 and V4 platforms. Security analysts estimate that at least nine separate crypto protocols had exposure to rsETH and were forced to suspend or limit services as a precaution.

Cyvers CEO Deddy Lavid said the event demonstrates how interconnected decentralized finance platforms can amplify damage when one protocol is compromised.

“This is exactly the kind of incident that highlights the risks of composability in DeFi,” Lavid noted.

Kelp had not released a detailed public statement beyond confirming the pause of contracts at the time of reporting.

The exploit adds to an already troubling year for crypto security. Industry data shows that losses from hacks, scams, and exploits reached approximately $482 million during the first quarter of 2026 alone.

Earlier this month, Drift Protocol suffered a separate attack that drained around $280 million. The platform later revealed the breach was the result of a long-term infiltration campaign, allegedly involving North Korean-linked operatives who built trust with team members before deploying malware on developer devices.

As DeFi ecosystems continue to expand, the Kelp breach serves as another warning that innovation without strong security controls can create vulnerabilities with ecosystem-wide consequences.