# CRYPTONEWS

191.5K
🚨 Whale Alert! A massive 2M UST just flowed into HyperLiquid, scooping up 50,080 $HYPE 🐋🔥 Big money is stepping in — signaling rising confidence, strong liquidity demand, and potential upside momentum. Eyes on $HYPE as whales make moves!
#CryptoWhale #HYPE #DeFi #CryptoNews #Altcoins
HYPE-0,52%
  • Reward
  • Comment
  • Repost
  • Share
#KelpDAOBridgeHacked
KelpDAO Bridge Exploit: Technical Breakdown & Industry Impact
On April 18, 2026, KelpDAO's rsETH cross-chain bridge suffered the largest DeFi exploit of 2026, with attackers draining approximately 116,500 rsETH valued at roughly $292 million. The incident represents approximately 18% of rsETH's total circulating supply and has triggered cascading effects across the DeFi ecosystem.
Attack Vector Analysis
The exploit was executed through a sophisticated multi-stage attack targeting LayerZero's infrastructure. Attackers first compromised two independent RPC nodes operated by
ZRO-0,67%
AAVE0,88%
ARB1,76%
ETH2,91%
BlackRiderCryptoLord
#KelpDAOBridgeHacked
KelpDAO Bridge Exploit: Technical Breakdown & Industry Impact
On April 18, 2026, KelpDAO's rsETH cross-chain bridge suffered the largest DeFi exploit of 2026, with attackers draining approximately 116,500 rsETH valued at roughly $292 million. The incident represents approximately 18% of rsETH's total circulating supply and has triggered cascading effects across the DeFi ecosystem.
Attack Vector Analysis
The exploit was executed through a sophisticated multi-stage attack targeting LayerZero's infrastructure. Attackers first compromised two independent RPC nodes operated by LayerZero Labs, replacing legitimate op-geth binaries with malicious versions. These poisoned nodes were specifically configured to deceive LayerZero's Decentralized Verifier Network (DVN) while maintaining truthful responses to other monitoring systems, effectively evading detection.
The attack sequence involved a coordinated DDoS strike against a third clean RPC node, forcing the DVN to failover to the compromised infrastructure. KelpDAO's bridge configuration utilized a 1-of-1 DVN setup, meaning only LayerZero Labs' DVN was required to validate cross-chain messages. The poisoned nodes successfully confirmed a fabricated burn transaction on Unichain, which the EndpointV2 relay system propagated to KelpDAO's OFT Adapter, triggering the unauthorized release of mainnet reserves.
Post-exploitation, the attacker systematically laundered the stolen rsETH across multiple wallets, depositing funds as collateral on Aave V3 markets across Ethereum and Arbitrum. The attacker secured approximately 75,700 WETH on Ethereum and 30,800 WETH on Arbitrum, achieving loan-to-value ratios near 99% before protocol-level freezes halted further borrowing.
Attribution & Threat Actor Profile
Security researchers and blockchain analytics firms have attributed the attack to North Korea's Lazarus Group, specifically the TraderTraitor cluster. The operational characteristics align with documented Lazarus methodologies: patient intrusion tactics, manipulation of trusted infrastructure, and sophisticated detection suppression mechanisms. The malware employed self-destructed following the exploit, systematically erasing forensic evidence from compromised systems.
Protocol Response & Containment
Aave responded within hours by freezing rsETH markets across V3 and V4 deployments, including SparkLend integration. The protocol currently faces approximately $177 million in bad debt, predominantly concentrated on Arbitrum. Total Value Locked across Aave ecosystem dropped from $26 billion to $18 billion, representing $8-14 billion in outflows as liquidity providers withdrew capital.
The contagion extended beyond Aave, with over 15 protocols implementing emergency bridge pauses. WETH lending pools experienced 100% utilization rates, creating secondary liquidation risks for leveraged positions. KelpDAO has blacklisted the exploiter addresses and claims to have prevented an additional $95 million in follow-up attack attempts.
Disputed Root Cause Analysis
A significant dispute exists between KelpDAO and LayerZero regarding fundamental responsibility. LayerZero maintains that KelpDAO's 1-of-1 DVN configuration deviated from recommended security practices, emphasizing that the protocol itself contained no vulnerabilities and that the incident was isolated to rsETH infrastructure. LayerZero has subsequently patched affected DVN and RPC systems.
KelpDAO counters that LayerZero's default documentation and quickstart configurations recommended the 1-of-1 setup, arguing that the infrastructure provider bears responsibility for RPC node security. Both parties agree that no smart contract bugs were exploited; the root cause centers on trust assumptions within single-point-of-failure configurations.
DeFi Security Implications
The incident exposes critical vulnerabilities in cross-chain bridge architectures, particularly regarding RPC infrastructure security. RPC nodes have emerged as a systemic weak link, with most protocols relying on a limited set of providers without adequate failover diversification. The exploit demonstrates that even sophisticated multi-signature and verification systems can be compromised when underlying data sources are poisoned.
Industry analysts recommend immediate implementation of multi-DVN configurations, diversified RPC provider networks, and real-time configuration auditing systems. The modular security architecture of LayerZero contained blast radius to rsETH specifically, with no other OFT or OApp contracts affected, suggesting that cross-chain messaging frameworks can maintain resilience even during targeted infrastructure attacks.
Current Status & Recovery Efforts
Aave governance is currently debating debt socialization mechanisms to address the bad debt situation. KelpDAO, LayerZero, and Aave have established coordination channels for recovery operations. Blockchain security collective Seal-911 is actively tracking fund movements, with portions of stolen assets identified flowing through Tornado Cash and other obfuscation protocols. Whitehat negotiation channels remain open, though no recovery has been confirmed at time of writing.
The exploit establishes a new record for 2026 DeFi hacks, surpassing the $285 million Drift Protocol incident from April 1. The incident reinforces ongoing concerns regarding bridge security as the primary attack vector in DeFi, with cross-chain infrastructure remaining the ecosystem's most contested security frontier.
#KelpDAO #DeFiSecurity #BridgeExploit #CryptoNews
repost-content-media
  • Reward
  • Comment
  • Repost
  • Share
#KelpDAOBridgeHacked
KelpDAO Bridge Exploit: Technical Breakdown & Industry Impact
On April 18, 2026, KelpDAO's rsETH cross-chain bridge suffered the largest DeFi exploit of 2026, with attackers draining approximately 116,500 rsETH valued at roughly $292 million. The incident represents approximately 18% of rsETH's total circulating supply and has triggered cascading effects across the DeFi ecosystem.
Attack Vector Analysis
The exploit was executed through a sophisticated multi-stage attack targeting LayerZero's infrastructure. Attackers first compromised two independent RPC nodes operated by
ZRO-0,67%
AAVE0,88%
ARB1,76%
ETH2,91%
BlackRiderCryptoLord
#KelpDAOBridgeHacked
KelpDAO Bridge Exploit: Technical Breakdown & Industry Impact
On April 18, 2026, KelpDAO's rsETH cross-chain bridge suffered the largest DeFi exploit of 2026, with attackers draining approximately 116,500 rsETH valued at roughly $292 million. The incident represents approximately 18% of rsETH's total circulating supply and has triggered cascading effects across the DeFi ecosystem.
Attack Vector Analysis
The exploit was executed through a sophisticated multi-stage attack targeting LayerZero's infrastructure. Attackers first compromised two independent RPC nodes operated by LayerZero Labs, replacing legitimate op-geth binaries with malicious versions. These poisoned nodes were specifically configured to deceive LayerZero's Decentralized Verifier Network (DVN) while maintaining truthful responses to other monitoring systems, effectively evading detection.
The attack sequence involved a coordinated DDoS strike against a third clean RPC node, forcing the DVN to failover to the compromised infrastructure. KelpDAO's bridge configuration utilized a 1-of-1 DVN setup, meaning only LayerZero Labs' DVN was required to validate cross-chain messages. The poisoned nodes successfully confirmed a fabricated burn transaction on Unichain, which the EndpointV2 relay system propagated to KelpDAO's OFT Adapter, triggering the unauthorized release of mainnet reserves.
Post-exploitation, the attacker systematically laundered the stolen rsETH across multiple wallets, depositing funds as collateral on Aave V3 markets across Ethereum and Arbitrum. The attacker secured approximately 75,700 WETH on Ethereum and 30,800 WETH on Arbitrum, achieving loan-to-value ratios near 99% before protocol-level freezes halted further borrowing.
Attribution & Threat Actor Profile
Security researchers and blockchain analytics firms have attributed the attack to North Korea's Lazarus Group, specifically the TraderTraitor cluster. The operational characteristics align with documented Lazarus methodologies: patient intrusion tactics, manipulation of trusted infrastructure, and sophisticated detection suppression mechanisms. The malware employed self-destructed following the exploit, systematically erasing forensic evidence from compromised systems.
Protocol Response & Containment
Aave responded within hours by freezing rsETH markets across V3 and V4 deployments, including SparkLend integration. The protocol currently faces approximately $177 million in bad debt, predominantly concentrated on Arbitrum. Total Value Locked across Aave ecosystem dropped from $26 billion to $18 billion, representing $8-14 billion in outflows as liquidity providers withdrew capital.
The contagion extended beyond Aave, with over 15 protocols implementing emergency bridge pauses. WETH lending pools experienced 100% utilization rates, creating secondary liquidation risks for leveraged positions. KelpDAO has blacklisted the exploiter addresses and claims to have prevented an additional $95 million in follow-up attack attempts.
Disputed Root Cause Analysis
A significant dispute exists between KelpDAO and LayerZero regarding fundamental responsibility. LayerZero maintains that KelpDAO's 1-of-1 DVN configuration deviated from recommended security practices, emphasizing that the protocol itself contained no vulnerabilities and that the incident was isolated to rsETH infrastructure. LayerZero has subsequently patched affected DVN and RPC systems.
KelpDAO counters that LayerZero's default documentation and quickstart configurations recommended the 1-of-1 setup, arguing that the infrastructure provider bears responsibility for RPC node security. Both parties agree that no smart contract bugs were exploited; the root cause centers on trust assumptions within single-point-of-failure configurations.
DeFi Security Implications
The incident exposes critical vulnerabilities in cross-chain bridge architectures, particularly regarding RPC infrastructure security. RPC nodes have emerged as a systemic weak link, with most protocols relying on a limited set of providers without adequate failover diversification. The exploit demonstrates that even sophisticated multi-signature and verification systems can be compromised when underlying data sources are poisoned.
Industry analysts recommend immediate implementation of multi-DVN configurations, diversified RPC provider networks, and real-time configuration auditing systems. The modular security architecture of LayerZero contained blast radius to rsETH specifically, with no other OFT or OApp contracts affected, suggesting that cross-chain messaging frameworks can maintain resilience even during targeted infrastructure attacks.
Current Status & Recovery Efforts
Aave governance is currently debating debt socialization mechanisms to address the bad debt situation. KelpDAO, LayerZero, and Aave have established coordination channels for recovery operations. Blockchain security collective Seal-911 is actively tracking fund movements, with portions of stolen assets identified flowing through Tornado Cash and other obfuscation protocols. Whitehat negotiation channels remain open, though no recovery has been confirmed at time of writing.
The exploit establishes a new record for 2026 DeFi hacks, surpassing the $285 million Drift Protocol incident from April 1. The incident reinforces ongoing concerns regarding bridge security as the primary attack vector in DeFi, with cross-chain infrastructure remaining the ecosystem's most contested security frontier.
#KelpDAO #DeFiSecurity #BridgeExploit #CryptoNews
repost-content-media
  • Reward
  • Comment
  • Repost
  • Share
Stonbassadors didn’t show up in March to participate, they showed up to take over.
14,692 STON distributed, roughly $4.8K
More than 600 contributors rewarded
Campaigns, contests, and meaningful content spread across the ecosystem
This goes beyond posting, it’s about building influence, sharpening strategy, and turning content into real impact
And this is only the beginning
Level up your X strategy
Expand across multiple platforms instead of staying in one lane
Focus on content that delivers real value, then improve it through feedback
If you’re serious about growing your voice in Web3, this is
  • Reward
  • Comment
  • Repost
  • Share
🚨 Gate Square Daily Breakdown | April 21 🚨
Let’s unpack today’s biggest narratives shaping crypto, macro, and market sentiment 👇
🌍 1️⃣ Geopolitics Update
Rising confidence around stability in the Strait of Hormuz is a quiet but powerful signal. A 68% probability of normalization suggests easing supply-chain fears, especially in oil markets. That reduces macro pressure — and crypto tends to love calmer global conditions.
📈 2️⃣ Market Momentum
Bitcoin pushing +2.4% is more than just a number — it’s continuation strength. With Bitcoin leading, assets like Ethereum, XRP, and Solana are follow
BTC2,16%
ETH2,91%
XRP0,55%
SOL3,15%
Gate_Square
📢 Gate Square Daily | April 21
1️⃣ Geopolitics: Polymarket odds for "Strait of Hormuz returning to normal by May 31" climb to 68%, up 9% in 24 hours .
2️⃣ Market Update: BTC rises ~2.4% over 24 hours, with ETH, XRP, SOL, and major altcoins following suit.
3️⃣ Crypto Regulation: US crypto market structure legislation hits a delay — Senate Banking Committee review unlikely before end of April.
4️⃣ Security Incident: Fallout from the Kelp exploit continues, with Aave's TVL dropping $8B, bad debt reaching ~$195M, and a wave of withdrawals triggered.
5️⃣ Platform News: Gate Pre-IPOs' SpaceX ($SPCX) offering hits a $300M subscription milestone.
repost-content-media
  • Reward
  • 12
  • Repost
  • Share
MasterChuTheOldDemonMasterChu:
Buy the dip and enter the market 😎
View More
#USIranTensionsShakeMarkets | Global Markets on Edge ⚠️🌍
The market isn’t reacting randomly—this is a full-scale geopolitical shockwave, and every asset class is feeling it.
🔥 What’s Happening (April 2026)
Tensions between the United States and Iran have escalated again after recent military incidents near the Strait of Hormuz—the world’s most critical oil route.
👉 This instantly triggered fear across global financial markets.
📉 Market Reaction
Crypto faced sudden selling pressure
Bitcoin slipped below key levels before stabilizing
Stocks turned red
Safe-haven demand (USD, oil) surged
👉 T
BTC2,16%
post-image
  • Reward
  • 19
  • Repost
  • Share
MrKing:
Buy To Earn 💰️
View More
#BitcoinBouncesBack #SaylorReleasesBitcoinTrackerUpdate | Smart Money Signal is Back 🚀
The market is watching closely—because whenever Michael Saylor drops a Bitcoin Tracker update, it’s never random.
📊 What Just Happened (April 21, 2026)
Saylor recently shared another Bitcoin Tracker signal with his famous message:
👉 “Think Even ₿igger”
Historically, this move comes BEFORE a major Bitcoin purchase announcement.
💰 And Guess What? The Pattern Already Played Out
Right after the signal:
👉 Strategy executed a massive $2.54 BILLION buy
👉 Added 34,164 BTC in just one week
👉 Total holdings no
BTC2,16%
  • Reward
  • 12
  • Repost
  • Share
ybaser:
To The Moon 🌕
View More
BlackRock Gives Strong Support to Bitcoin: “Non-Sovereign Global Decentralized Asset”
✨ Jay Jacobs, Head of BlackRock US Equity ETFs, described Bitcoin as a non-sovereign global decentralized asset that adds real value to portfolios.
✨ “Bitcoin is governed by its own rules, which gives it a significant advantage against geopolitical or inflationary risks,” he said.
✨ He emphasized that “Bitcoin’s value will increase as we see more currency devaluations, rising government debt, and increased demand for cross-border asset transfers.”
✨ These statements clearly demonstrate BlackRock’s view of Bit
BTC2,16%
post-image
post-image
  • Reward
  • 9
  • Repost
  • Share
discovery:
LFG 🔥
View More
#SaylorReleasesBitcoinTrackerUpdate
The latest update to the Bitcoin Tracker has sparked widespread discussion across the crypto and financial communities. This release is being seen as another significant step toward increasing transparency, accessibility, and strategic insight into Bitcoin holdings and market movements. As institutional interest in Bitcoin continues to grow, tools like this tracker are becoming increasingly important for investors, analysts, and enthusiasts who want a clearer understanding of how major players interact with the market.
At its core, the Bitcoin Tracker update
BTC2,16%
post-image
  • Reward
  • Comment
  • Repost
  • Share
#KelpDAOBridgeHacked
The KelpDAO bridge has reportedly been hacked, raising serious concerns across the crypto community. Users are urged to stay cautious as details continue to emerge about the scale of the breach and potential losses.
Security remains a top priority—always double-check transactions and avoid interacting with suspicious links during uncertain times.
#CryptoNews #BlockchainSecurity #StaySafe
  • Reward
  • Comment
  • Repost
  • Share
Load More