{"id":73303,"date":"2026-04-19T06:37:27","date_gmt":"2026-04-18T23:37:27","guid":{"rendered":"https:\/\/hbbgroup.net\/kelp-restaking-platform-exploited-293m-drained-in-attack\/"},"modified":"2026-04-19T06:37:27","modified_gmt":"2026-04-18T23:37:27","slug":"kelp-restaking-platform-exploited-293m-drained-in-attack","status":"publish","type":"post","link":"https:\/\/hbbgroup.net\/vi\/kelp-restaking-platform-exploited-293m-drained-in-attack\/","title":{"rendered":"Kelp restaking platform exploited, $293M drained in attack"},"content":{"rendered":"<div data-testid=\"html-renderer-container\">\n<p>Kelp, a liquid restaking protocol, was the victim of a cyber attack on Saturday, causing the platform to pause smart contracts for its restaking token (rsETH), as it \u201cinvestigates\u201d the attack amid reports of hundreds of millions of dollars in losses.<\/p>\n<p>\u201cEarlier today, we identified suspicious cross-chain activity involving rsETH. We have paused rsETH contracts across mainnet and several Layer-2s,\u201d the Kelp platform <a title=\"https:\/\/x.com\/KelpDAO\/status\/2045595819035046148\" href=\"https:\/\/x.com\/KelpDAO\/status\/2045595819035046148\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> in an X post.<\/p>\n<p>The attacker exploited the rsETH adapter bridge contract, the software code that manages Kelp\u2019s rsETH token, and drained the platform of about $293 million in funds, <a title=\"https:\/\/x.com\/CyversAlerts\/status\/2045596550882001142\" href=\"https:\/\/x.com\/CyversAlerts\/status\/2045596550882001142\" target=\"_blank\" rel=\"nofollow noopener\">according<\/a> to blockchain security firm Cyvers.<\/p>\n<figure><img decoding=\"async\" alt=\"Cybercrime, Cybersecurity, Scams, Hacks\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2026-04\/019da280-0ed5-7456-91ac-c7984722b288.png\"><figcaption><em>Source: <\/em><a title=\"https:\/\/x.com\/CyversAlerts\/status\/2045596550882001142\" href=\"https:\/\/x.com\/CyversAlerts\/status\/2045596550882001142\" target=\"_blank\" rel=\"nofollow noopener\"><em>Cyvers<\/em><\/a><\/figcaption><\/figure>\n<p>The attacker used a Tornado Cash crypto mixer-funded address and has already converted about $250 million of the stolen funds to Ether (<a title=\"https:\/\/cointelegraph.com\/price-indexes\/ethereum\" href=\"https:\/\/cointelegraph.com\/price-indexes\/ethereum\">ETH<\/a>), the native cryptocurrency of the Ethereum layer-1 blockchain network, Cyvers told Cointelegraph.<\/p>\n<p>In response to the attack, decentralized finance (DeFi) platform Aave announced it had <a title=\"https:\/\/x.com\/aave\/status\/2045593585966252377\" href=\"https:\/\/x.com\/aave\/status\/2045593585966252377\" target=\"_blank\" rel=\"nofollow noopener\">frozen<\/a> rsETH markets on Aave V3 and V4. At least nine crypto protocols had exposure to the token and have frozen activity on their platforms in response, Cyvers said.<\/p>\n<figure><img decoding=\"async\" alt=\"Cybercrime, Cybersecurity, Scams, Hacks\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2026-04\/019da281-4f8d-7c94-974c-efd40d6d06d6.png\"><figcaption><em>Source: <\/em><a title=\"https:\/\/x.com\/aave\/status\/2045593585966252377\" href=\"https:\/\/x.com\/aave\/status\/2045593585966252377\" target=\"_blank\" rel=\"nofollow noopener\"><em>Aave<\/em><\/a><\/figcaption><\/figure>\n<p>\u201cThis is exactly the kind of incident that highlights the risks of composability in DeFi,\u201d Deddy Lavid, CEO of Cyvers, told Cointelegraph. Cointelegraph reached out to Kelp but did not obtain a response by the time of publication.\u00a0<\/p>\n<p>The incident is the latest in a <a title=\"https:\/\/cointelegraph.com\/news\/12-crypto-protocol-entities-attacked-since-drift-exploit\" href=\"https:\/\/cointelegraph.com\/news\/12-crypto-protocol-entities-attacked-since-drift-exploit\">string of cybersecurity hacks and exploits<\/a> of crypto platforms over the last several months, as crypto losses from hacks and scams <a title=\"https:\/\/cointelegraph.com\/news\/web3-hacks-cost-464-million-in-q1-hacken\" href=\"https:\/\/cointelegraph.com\/news\/web3-hacks-cost-464-million-in-q1-hacken\">totaled about $482 million<\/a> in Q1 2026.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a title=\"https:\/\/cointelegraph.com\/news\/fake-ledger-app-apple-app-store-9-5m-crypto-theft-zachxbt\" href=\"https:\/\/cointelegraph.com\/news\/fake-ledger-app-apple-app-store-9-5m-crypto-theft-zachxbt\"><em><strong>Fake Ledger Live app on Apple App Store drained $9.5M from victims: ZachXBT<\/strong><\/em><\/a><\/p>\n<h2>Drift Protocol hacked for $280 million<\/h2>\n<p>Decentralized cryptocurrency exchange Drift Protocol also <a title=\"https:\/\/cointelegraph.com\/news\/drift-protocol-pause-deposit-unusual-activity\" href=\"https:\/\/cointelegraph.com\/news\/drift-protocol-pause-deposit-unusual-activity\">suffered an exploit<\/a> in April, which <a title=\"https:\/\/cointelegraph.com\/news\/drift-280-million-hack-questions-circle-response\" href=\"https:\/\/cointelegraph.com\/news\/drift-280-million-hack-questions-circle-response\">drained the platform of about $280 million<\/a>.<\/p>\n<p>The Drift Protocol team said the attack took \u201c<a title=\"https:\/\/cointelegraph.com\/news\/drift-protocol-exploit-preparation-preliminary-findings\" href=\"https:\/\/cointelegraph.com\/news\/drift-protocol-exploit-preparation-preliminary-findings\">months of deliberate preparation<\/a>,\u201d in which the team was infiltrated by suspected <a title=\"https:\/\/cointelegraph.com\/news\/dprk-workers-have-worked-on-countless-protocols-since-defi-summer-cybersec-analyst\" href=\"https:\/\/cointelegraph.com\/news\/dprk-workers-have-worked-on-countless-protocols-since-defi-summer-cybersec-analyst\">North Korean state-affiliated hackers<\/a>.<\/p>\n<p>In a post-mortem <a title=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409\" href=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409\" target=\"_blank\" rel=\"nofollow noopener\">update<\/a>, the Drift team said they met the attackers at a \u201cmajor\u201d crypto conference and collaborated with them for several months before the attackers deployed malware on developer machines and compromised the platform.\u00a0<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a title=\"https:\/\/cointelegraph-magazine.com\/defis-billion-dollar-secret-the-insiders-responsible-for-hacks\/\" href=\"https:\/\/cointelegraph-magazine.com\/defis-billion-dollar-secret-the-insiders-responsible-for-hacks\/\" target=\"_blank\" rel=\"nofollow noopener\"><em><strong>DeFi\u2019s billion-dollar secret: The insiders responsible for hacks<\/strong><\/em><\/a><\/p>\n<p><template data-type=\"defi_newsletter\" data-name=\"subscription_form\" data-label=\"Subscription Form: DeFi Newsletter\"><\/template><\/div>\n<p>Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph\u2019s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy <a href=\"http:\/\/cointelegraph.com\/editorial-policy\">https:\/\/cointelegraph.com\/editorial-policy<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Kelp, a liquid restaking protocol, was the victim of a cyber attack on Saturday, causing the platform to pause smart [&hellip;]<\/p>","protected":false},"author":5,"featured_media":73304,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[220],"tags":[],"class_list":["post-73303","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tien-dien-tu"],"acf":[],"_links":{"self":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts\/73303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/comments?post=73303"}],"version-history":[{"count":0,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts\/73303\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/media\/73304"}],"wp:attachment":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/media?parent=73303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/categories?post=73303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/tags?post=73303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}