rsETH LayerZero bridge hacked, Aave and other protocols urgently freeze funds

MarketWhisper
ZRO-3%
AAVE-0,86%
ETH0,08%
ARB1,77%

rsETH黑客事件

Kelp DAO’s liquidity re-staking token rsETH’s LayerZero cross-chain bridge was attacked by hackers on April 19 (Saturday), 2026—marking the largest DeFi security incident to date this year. Multiple major DeFi protocols have responded with emergency measures one after another, freezing or pausing LayerZero-related functionality.

Attack Mechanism: Forged Cross-Chain Messages Bypass Bridge Contract Verification

The core of this attack lies in a vulnerability in LayerZero message verification. By forging what appear to be legitimate cross-chain messages, the attackers caused the bridge contract to mistakenly believe it had received a valid request, directly releasing 116,500 rsETH to an address controlled by the attacker. This attack pattern did not directly compromise the smart contracts of lending protocols such as Aave. Instead, the attackers only needed to deposit the stolen assets as “legitimate” collateral to borrow a large amount of WETH, creating an exposure to bad debts that the affected protocols may be unable to fully recover.

Emergency Measures by Major Protocols — Overview

Aave: rsETH remains frozen on V3 and V4; rsETH on the Ethereum mainnet has full collateral support; WETH reserves are frozen in the affected markets (Ethereum, Arbitrum, Base, Mantle, Linea) as well; solutions are being actively assessed.

Ethena: Extends the pause period of the LayerZero OFT bridge; confirms that USDe collateral support remains above 100%.

Fluid: Launches an aWETH redemption agreement, allowing ETH lenders to redeem for wstETH or weETH, restoring liquidity and reducing liquidation risk. The initial capacity limit is $1 billion in ETH.

Morpho: Pauses the MORPHO OFT bridge on Arbitrum; smart contract security remains sound, with risk exposure of only about $1 million (distributed across 2 isolated markets). The fully isolated-market design ensures other Vaults are not affected.

Curve Finance: Pauses the LayerZero infrastructure, affecting the bridging of CRV from chains such as BNB, Sonic, and Avalanche, as well as the rapid bridging of crvUSD (the L2 slow bridge is still functioning normally).

Reserve: Temporarily suspends the minting, rebalancing, and RSR redemptions of eUSD and USD3; the redemption feature remains normally open; ETH+ and bsdETH contain no rsETH collateral, representing zero risk.

Protocols Confirmed Not Affected: Maple Finance (syrupUSDC and syrupUSDT unaffected), Polygon ecosystem (including Katana, Vaultbridge), and EtherFi protocol liquidity vaults have all confirmed there is no loss risk. As a precautionary measure, Hyperwave (the Hyperliquid ecosystem) has temporarily paused LayerZero bridging.

LayerZero Official Statement and Next Steps

LayerZero said it has fully understood the rsETH vulnerability incident, has been actively working with KelpDAO on repairs since the event occurred, and confirmed that other applications remain secure. After obtaining all information, LayerZero plans to jointly publish a complete post-incident analysis report with KelpDAO.

Frequently Asked Questions

How was the attack on the rsETH LayerZero bridge specifically carried out?

The attackers forged LayerZero cross-chain messages, causing the bridge contract to mistakenly treat them as legitimate requests, directly releasing 116,500 rsETH to an address controlled by the attacker. The attack did not directly break the lending protocols themselves, such as Aave; instead, it used the stolen rsETH as collateral to borrow WETH, creating unsecured bad-debt exposure on the protocol’s loan ledger.

What is the current status of rsETH on Aave, and when might it be restored?

rsETH on Aave V3 and V4 is still in a frozen state; WETH reserves are frozen in parallel across the Ethereum, Arbitrum, Base, Mantle, and Linea markets. Aave stated that rsETH on the Ethereum mainnet has full collateral support, but it has not yet announced a clear timeline for restoration. It is currently actively evaluating potential solutions.

Which protocols confirmed they were not affected by this incident?

Polygon ecosystem (including Agglayer, Katana, Vaultbridge), EtherFi protocol liquidity vaults, Maple Finance’s syrupUSDT and syrupUSDC, as well as Reserve’s ETH+ and bsdETH are all confirmed to have no rsETH exposure. All of Morpho’s other Vaults are also confirmed unaffected due to the isolated-market design; only two isolated markets have limited exposure of about $1 million.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Ethereum Phishing Attack Drains $585K From Four Users, Single Victim Loses $221K WBTC

A coordinated Ethereum phishing attack drained $585,000 from four victims, exploiting user permissions through a deceptive link. This incident highlights the rapid loss of funds via social engineering, even under the guise of legitimacy.

GateNews1h ago

Pay attention to the signed content! Vercel is hit with ransomware demanding $2 million, and crypto protocol frontend security raises a red flag

The cloud development platform Vercel was breached by hackers on April 19. The attackers gained access through a third-party AI tool used by employees and threatened to extort $2 million. Although sensitive data was not accessed, other data may have been used. The incident has raised security concerns in the crypto community, and Vercel is currently investigating while advising users to rotate their keys.

ChainNewsAbmedia2h ago

KelpDAO Loses $290M in Lazarus Group LayerZero Attack

KelpDAO faced a $290 million loss due to a sophisticated security breach linked to the Lazarus Group. The attack exploited configuration weaknesses in their verification system and highlighted the risks of relying on a single-point verification setup. Industry experts emphasize the need for improved security configurations and multi-layer verification to prevent future incidents.

CryptoFrontier3h ago

LayerZero responds to Kelp DAO’s 292 million incident: it indicates that Kelp set up a custom 1-of-1 DVN configuration, and the attacker was North Korea’s Lazarus.

LayerZero issued a statement regarding the $292 million hack suffered by Kelp DAO, accusing Kelp’s self-selected 1-of-1 DVN configuration of making the incident possible. The attacker was the North Korean Lazarus Group. LayerZero emphasized that this incident stems from configuration choices and that it will no longer support this kind of vulnerable setup. In addition, responsibility is still disputed, and no compensation plan has been provided.

ChainNewsAbmedia3h ago

DeFi hackers stole $600 million in April; Kelp DAO and Drift accounted for 95% of the monthly losses

In April 2026, within just 20 days, cryptocurrency protocols suffered losses of more than $606 million due to hacker attacks, becoming the worst single-month loss record since the February 2025 exchange incident in which $1.4 billion in data was leaked. The two attacks by KelpDAO and Drift Protocol accounted for 95% of April’s losses, and 75% of the total $771.8 million losses as of now in 2026.

MarketWhisper3h ago

Vercel Breach Linked to AI Tool Context.ai Compromise Raises Risk for Crypto Frontends

Vercel confirmed a security breach caused by a compromised AI tool, leading to the theft of employee and customer data. The incident poses risks to the Web3 ecosystem, and the attacker is attempting to sell the stolen data for $2 million. Vercel is addressing the situation with law enforcement and incident response experts.

GateNews4h ago
Comment
0/400
No comments