Kelp DAO Restores rsETH After $293M Exploit, Aave TVL Still Down
Kelp DAO Restores rsETH After $293 Million Exploit – Recovery Effort Highlights DeFi Interconnectedness
Key Takeaways
- Kelp DAO says its restaked Ether token rsETH has been fully restored five weeks after a $293 million exploit on April 18.
- The final tranche of 20,373.7 rsETH was sent to the LayerZero smart contract, closing the operational recovery plan.
- The attacker used 116,500 rsETH as collateral on Aave, contributing to $190 million in bad debt and major liquidity disruptions.
- Aave’s total value locked fell from $26.4 billion to below $14 billion and has not recovered since the incident.
Kelp DAO Completes rsETH Recovery After April Exploit
Kelp DAO has announced the completion of its recovery process for its restaked Ether token, rsETH, following a $293 million exploit that took place on April 18. The attack was attributed to North Korea’s Lazarus Group.
According to Kelp DAO, the final tranche of 20,373.7 rsETH was transferred to the LayerZero smart contract responsible for locking, minting, burning and releasing rsETH during cross chain transfers. The protocol stated that this transfer closes the operational part of its rsETH recovery plan.
The exploit triggered a five week recovery effort. Earlier in the process, on May 13, Kelp DAO transferred an initial tranche of 25,000 rsETH. That move allowed bridging between the Ethereum mainnet and the network’s layer 2 blockchains to reopen. Withdrawals for rsETH resumed the following day.
Kelp DAO reported that since reopening withdrawals, rsETH mints, redemptions and reward operations have been running normally. Several crypto protocols contributed funds under the DeFi United initiative to help restore the token’s backing.
Ripple Effects Across the Crypto Lending Market
The April exploit did not remain isolated to Kelp DAO. It triggered a broader liquidity shock across decentralized finance markets and renewed concerns about the interconnected nature of DeFi protocols.
The attacker stole 116,500 rsETH and used a large portion of those tokens as collateral on the Aave lending platform. By borrowing wrapped Ether against this collateral, the attacker left Aave with $190 million in bad debt. The situation prompted a wave of withdrawals from the platform.
The incident illustrates how vulnerabilities in one protocol can cascade into others when tokens are widely used as collateral across lending markets. In this case, rsETH was integrated into Aave’s lending infrastructure, amplifying the financial impact beyond Kelp DAO itself.
The Kelp DAO exploit was one of 25 crypto hacks recorded in April. Combined losses across those incidents reached $630 million, making it the worst month for crypto related hacks since February 2025. In that earlier month, crypto exchange Bybit suffered a record $1.5 billion hack.
Aave’s Total Value Locked Remains Under Pressure
Aave was among the protocols most affected by the fallout. Before the exploit, Aave’s total value locked stood at $26.4 billion. Following the incident and the associated withdrawals, that figure fell to below $14 billion.
The decline also cost Aave its long held position as the largest DeFi protocol by total value locked. Data from DefiLlama shows that while net outflows from Aave’s lending markets have eased over the past month, the protocol’s total value locked has not recovered.
Since about one week after the exploit, Aave’s TVL has fluctuated within a narrow range between $13.9 billion and $15.1 billion. The stabilization suggests that the initial wave of withdrawals has slowed, but the platform has not regained the capital it held prior to the Kelp DAO incident.
For users who interact with DeFi lending markets, total value locked serves as a key indicator of available liquidity and market confidence. A sustained reduction in TVL can affect borrowing capacity, collateral requirements and overall market dynamics within decentralized lending ecosystems.
Operational Status of rsETH and Cross Chain Transfers
With the final tranche now transferred to the LayerZero smart contract, Kelp DAO states that the operational component of its recovery is complete. The smart contract plays a central role in managing rsETH across different blockchains by handling locking, minting, burning and releasing functions during cross chain transfers.
The reopening of bridging between Ethereum mainnet and layer 2 networks marked a significant milestone in the recovery process. Restoring cross chain functionality is critical for tokens like rsETH that are used across multiple decentralized applications and lending platforms.
Kelp DAO’s confirmation that minting, redemption and reward mechanisms are functioning normally signals a return to standard protocol operations, at least from an operational standpoint. The recovery was supported by contributions from several crypto protocols through the DeFi United initiative, aimed at restoring the token’s backing after the exploit.
Our Assessment
Kelp DAO has completed the operational phase of restoring rsETH five weeks after a $293 million exploit attributed to the Lazarus Group. The incident had significant spillover effects, particularly on Aave, where the use of stolen rsETH as collateral contributed to $190 million in bad debt and a sharp drop in total value locked.
While Kelp DAO reports that rsETH minting, redemptions and rewards are functioning normally again, Aave’s total value locked remains well below pre exploit levels. The episode underscores how security breaches in one DeFi protocol can affect liquidity and stability across interconnected platforms.