rsETH LayerZero bridge hacked, Aave and other protocols urgently freeze funds

MarketWhisper
ZRO5,01%
AAVE-0,82%
ETH-2,31%
ARB-1,57%

rsETH黑客事件

Kelp DAO’s liquidity re-staking token rsETH’s LayerZero cross-chain bridge was attacked by hackers on April 19 (Saturday), 2026—marking the largest DeFi security incident to date this year. Multiple major DeFi protocols have responded with emergency measures one after another, freezing or pausing LayerZero-related functionality.

Attack Mechanism: Forged Cross-Chain Messages Bypass Bridge Contract Verification

The core of this attack lies in a vulnerability in LayerZero message verification. By forging what appear to be legitimate cross-chain messages, the attackers caused the bridge contract to mistakenly believe it had received a valid request, directly releasing 116,500 rsETH to an address controlled by the attacker. This attack pattern did not directly compromise the smart contracts of lending protocols such as Aave. Instead, the attackers only needed to deposit the stolen assets as “legitimate” collateral to borrow a large amount of WETH, creating an exposure to bad debts that the affected protocols may be unable to fully recover.

Emergency Measures by Major Protocols — Overview

Aave: rsETH remains frozen on V3 and V4; rsETH on the Ethereum mainnet has full collateral support; WETH reserves are frozen in the affected markets (Ethereum, Arbitrum, Base, Mantle, Linea) as well; solutions are being actively assessed.

Ethena: Extends the pause period of the LayerZero OFT bridge; confirms that USDe collateral support remains above 100%.

Fluid: Launches an aWETH redemption agreement, allowing ETH lenders to redeem for wstETH or weETH, restoring liquidity and reducing liquidation risk. The initial capacity limit is $1 billion in ETH.

Morpho: Pauses the MORPHO OFT bridge on Arbitrum; smart contract security remains sound, with risk exposure of only about $1 million (distributed across 2 isolated markets). The fully isolated-market design ensures other Vaults are not affected.

Curve Finance: Pauses the LayerZero infrastructure, affecting the bridging of CRV from chains such as BNB, Sonic, and Avalanche, as well as the rapid bridging of crvUSD (the L2 slow bridge is still functioning normally).

Reserve: Temporarily suspends the minting, rebalancing, and RSR redemptions of eUSD and USD3; the redemption feature remains normally open; ETH+ and bsdETH contain no rsETH collateral, representing zero risk.

Protocols Confirmed Not Affected: Maple Finance (syrupUSDC and syrupUSDT unaffected), Polygon ecosystem (including Katana, Vaultbridge), and EtherFi protocol liquidity vaults have all confirmed there is no loss risk. As a precautionary measure, Hyperwave (the Hyperliquid ecosystem) has temporarily paused LayerZero bridging.

LayerZero Official Statement and Next Steps

LayerZero said it has fully understood the rsETH vulnerability incident, has been actively working with KelpDAO on repairs since the event occurred, and confirmed that other applications remain secure. After obtaining all information, LayerZero plans to jointly publish a complete post-incident analysis report with KelpDAO.

Frequently Asked Questions

How was the attack on the rsETH LayerZero bridge specifically carried out?

The attackers forged LayerZero cross-chain messages, causing the bridge contract to mistakenly treat them as legitimate requests, directly releasing 116,500 rsETH to an address controlled by the attacker. The attack did not directly break the lending protocols themselves, such as Aave; instead, it used the stolen rsETH as collateral to borrow WETH, creating unsecured bad-debt exposure on the protocol’s loan ledger.

What is the current status of rsETH on Aave, and when might it be restored?

rsETH on Aave V3 and V4 is still in a frozen state; WETH reserves are frozen in parallel across the Ethereum, Arbitrum, Base, Mantle, and Linea markets. Aave stated that rsETH on the Ethereum mainnet has full collateral support, but it has not yet announced a clear timeline for restoration. It is currently actively evaluating potential solutions.

Which protocols confirmed they were not affected by this incident?

Polygon ecosystem (including Agglayer, Katana, Vaultbridge), EtherFi protocol liquidity vaults, Maple Finance’s syrupUSDT and syrupUSDC, as well as Reserve’s ETH+ and bsdETH are all confirmed to have no rsETH exposure. All of Morpho’s other Vaults are also confirmed unaffected due to the isolated-market design; only two isolated markets have limited exposure of about $1 million.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

KelpDAO Loses $290M in Lazarus Group LayerZero Attack

KelpDAO faced a $290 million loss due to a sophisticated security breach linked to the Lazarus Group. The attack exploited configuration weaknesses in their verification system and highlighted the risks of relying on a single-point verification setup. Industry experts emphasize the need for improved security configurations and multi-layer verification to prevent future incidents.

CryptoFrontier16m ago

LayerZero responds to Kelp DAO’s 292 million incident: it indicates that Kelp set up a custom 1-of-1 DVN configuration, and the attacker was North Korea’s Lazarus.

LayerZero issued a statement regarding the $292 million hack suffered by Kelp DAO, accusing Kelp’s self-selected 1-of-1 DVN configuration of making the incident possible. The attacker was the North Korean Lazarus Group. LayerZero emphasized that this incident stems from configuration choices and that it will no longer support this kind of vulnerable setup. In addition, responsibility is still disputed, and no compensation plan has been provided.

ChainNewsAbmedia23m ago

DeFi hackers stole $600 million in April; Kelp DAO and Drift accounted for 95% of the monthly losses

In April 2026, within just 20 days, cryptocurrency protocols suffered losses of more than $606 million due to hacker attacks, becoming the worst single-month loss record since the February 2025 exchange incident in which $1.4 billion in data was leaked. The two attacks by KelpDAO and Drift Protocol accounted for 95% of April’s losses, and 75% of the total $771.8 million losses as of now in 2026.

MarketWhisper26m ago

Vercel Breach Linked to AI Tool Context.ai Compromise Raises Risk for Crypto Frontends

Vercel confirmed a security breach caused by a compromised AI tool, leading to the theft of employee and customer data. The incident poses risks to the Web3 ecosystem, and the attacker is attempting to sell the stolen data for $2 million. Vercel is addressing the situation with law enforcement and incident response experts.

GateNews1h ago

Ripple CTO: Kelp DAO Exploit Reflects Bridge Security Trade-Offs

David Schwartz, CTO Emeritus at Ripple, analyzed bridge security vulnerabilities following the $292 million Kelp DAO exploit. He noted that providers prioritized convenience over robust security, undermining essential protective features. The Kelp DAO breach stemmed from a private key leak, exacerbated by a simplified security configuration in their LayerZero implementation.

CryptoFrontier3h ago

France Logs 41 Crypto-Related Kidnappings and Home Invasions in 2025

In 2025, France documented 41 crypto-related kidnappings amid rising "wrench attacks," prompting heightened security around blockchain events. Global incidents of coercion surged by 75%, with France leading in cases. Efforts to improve safety and address concerns about becoming a crypto hub are underway.

GateNews3h ago
Comment
0/400
No comments