Kelp DAO Announces rsETH Recovery Following $293 Million Security Breach

In a resilient comeback, Kelp DAO has restored full functionality to its Ethereum-based rsETH operations, following a massive $293 million loss due to a cyberattack linked to North Korea's Lazarus Group. This recovery marks a crucial stabilization effort for the protocol after a harrowing five-week saga that also strained the broader decentralized finance (DeFi) sector.

Radom Team

May 26, 2026

After a significant security breach resulting in a loss of nearly $293 million, Kelp DAO has successfully completed a recovery effort for its restaked Ether token (rsETH), a crucial component in its Ethereum liquid staking protocol. This recovery caps a tense five-week period following an exploit attributed to North Korea's Lazarus Group. According to a recent update from Kelp DAO, all operations concerning rsETH mints, redemptions, and rewards are now functioning as intended, marking a pivotal step in stabilizing the protocol post-incident.

The financial shockwaves of the April exploit extended beyond Kelp DAO, notably impacting the decentralized finance (DeFi) realm, particularly Aave. The attacker utilized stolen rsETH as collateral on Aave’s platform, thereby extracting a substantial amount of Wrapped Ether and leaving behind nearly $190 million in uncollateralized debt. This incident triggered an acute liquidity crisis, illustrating the vulnerability of interconnected DeFi systems to single points of failure. In addressing these intertwined risks, CoinTelegraph reports that numerous crypto protocols under the DeFi United initiative rallied to replenish rsETH's reserves, a testament to the sector's collaborative spirit in times of crisis.

Furthermore, the aftermath of this exploit significantly dented the total value locked (TVL) in Aave, causing it to plummet from $26.4 billion to under $14 billion. While the bleeding of Aave’s TVL has since slowed, a recovery in these figures has yet to materialize, hovering persistently between $13.9 billion and $15.1 billion. This stagnation underscores the lasting impact of security breaches on investor confidence and the essential demand for enhanced protective measures within DeFi protocols.

As the dust settles, Kelp DAO's ability to swiftly address and rectify the rsETH shortfall is commendable. However, the incident serves as a stark reminder of the fragility of DeFi ecosystems to cyber-attacks. Moving forward, it is imperative for such platforms to not only enhance their security protocols but also to foster robust recovery strategies that can swiftly restore system and user equilibriums without external assistance. Additionally, these episodes accentuate the need for more rigorous regulatory frameworks that can preempt, address, and mitigate the ramifications of such attacks on a systemic level.

In light of these challenges, services like Radom’s on- and off-ramping solutions become increasingly relevant. They offer secure, compliant gateways for converting between crypto and fiat currencies, which can help buffer against the impacts of such breaches by providing more stable and reliable liquidity options in tumultuous times.

The resilience of DeFi is not just about rebounding from setbacks but also about learning and adapting from them to forge more robust, efficient, and secure systems that can withstand the complexities of the modern financial landscape.

Sign up to Radom to get started