Binance Square
#hack

hack

955,477 views
647 ກຳລັງສົນທະນາ
ImCryptOpus
·
--
📊 #DeFi TVL dropped $14B in 48 hours after the KelpDAO hack. Aave alone lost $10B in deposits. The question nobody is asking: cyclical fear, or structural repricing? #Network Stress Index is at the highest reading since FTX. If cyclical, we're near the pain bottom. If structural, #DeFi just entered a new regime. 3 signals that tell us within 7 days: • Stablecoin inflows into DEXes • Aave borrow rates normalizing • TVL/marketcap ratio recovery Real-time #Network Stress → #hack #crypto
📊 #DeFi TVL dropped $14B in 48 hours after the KelpDAO hack. Aave alone lost $10B in deposits. The question nobody is asking: cyclical fear, or structural repricing? #Network Stress Index is at the highest reading since FTX. If cyclical, we're near the pain bottom. If structural, #DeFi just entered a new regime. 3 signals that tell us within 7 days:

• Stablecoin inflows into DEXes

• Aave borrow rates normalizing

• TVL/marketcap ratio recovery

Real-time #Network Stress → #hack

#crypto
$BTC {spot}(BTCUSDT) #Hack ⚠️ Hacker Exploits Trezor Wallet for $75M Crypto A hacker has breached a Trezor hardware wallet to access $75 million in cryptocurrency, following a previous hack involving a wallet holding $66 million. Joe Grand spent three years refining a recovery method for hardware wallets that users had locked years ago. This technique was originally developed in 2017 by a 15-year-old from the UK, who created it in his bedroom and used it to help a Wired site editor recover $30,000. Now, nine years later, the same exploit is saving millions in Trezor wallets. Such work could demand up to half of the wallet’s remaining balance as a fee.
$BTC
#Hack ⚠️ Hacker Exploits Trezor Wallet for $75M Crypto

A hacker has breached a Trezor hardware wallet to access $75 million in cryptocurrency, following a previous hack involving a wallet holding $66 million.

Joe Grand spent three years refining a recovery method for hardware wallets that users had locked years ago. This technique was originally developed in 2017 by a 15-year-old from the UK, who created it in his bedroom and used it to help a Wired site editor recover $30,000.

Now, nine years later, the same exploit is saving millions in Trezor wallets. Such work could demand up to half of the wallet’s remaining balance as a fee.
🚨 BREAKING: Arbitrum Freezes $71 Million! 🚨 Security Council votes to lock 30,766 ETH linked to the Kelp DAO hack 🛑💸 The Details: 🔹 Funds traced to hackers (suspected Lazarus Group) 🔹 Vote passed 9-3 to protect the ecosystem 🔹 Assets now frozen & cannot be moved 🔥 The Big Debate: Is this necessary security action... or proof that L2s are NOT fully decentralized? 🤔 $ETH $ARB $OP #Arbitrum #KelpDAO #Hack #Security
🚨 BREAKING: Arbitrum Freezes $71 Million! 🚨

Security Council votes to lock 30,766 ETH linked to the Kelp DAO hack 🛑💸

The Details:
🔹 Funds traced to hackers (suspected Lazarus Group)
🔹 Vote passed 9-3 to protect the ecosystem
🔹 Assets now frozen & cannot be moved

🔥 The Big Debate:
Is this necessary security action... or proof that L2s are NOT fully decentralized? 🤔
$ETH $ARB $OP
#Arbitrum #KelpDAO #Hack #Security
🔥PÁNICO EN DEFI: RETIROS MASIVOS Y DEUDA MILLONARIA 👀 El pánico extremo y el FUD se apoderaron de las finanzas descentralizadas dejando pérdidas colosales y una deuda tóxica gigantesca en el ecosistema. Un exploit letal permitió a atacantes infiltrarse y hacer retiros de tokens. Si tienes criptomonedas en protocolos de préstamos, necesitas ver esto ahora mismo para entender quién asumirá el golpe y cómo protegerte. #ciberseguridad #blockchain #AAVE #Hack $AAVE
🔥PÁNICO EN DEFI: RETIROS MASIVOS Y DEUDA MILLONARIA 👀
El pánico extremo y el FUD se apoderaron de las finanzas descentralizadas dejando pérdidas colosales y una deuda tóxica gigantesca en el ecosistema. Un exploit letal permitió a atacantes infiltrarse y hacer retiros de tokens. Si tienes criptomonedas en protocolos de préstamos, necesitas ver esto ahora mismo para entender quién asumirá el golpe y cómo protegerte. #ciberseguridad
#blockchain
#AAVE
#Hack
$AAVE
Most traders using 20-100x leverage don't realise how much they're leaking in fees every month. We ran the numbers across Bybit, Binance and BYDFi and the difference between the most and least expensive platform adds up to $2,000 in savings every single month. That's not trading profits — that's just money you're giving away unnecessarily in fees. If you're trading at any serious volume, switching platform alone could be the most profitable move you make this year. The exact calculations: https://trading365.org/guides/the-bybit-weex-bydfi-fee-hack-how-to-save-2000-monthly-on-20-100x-leverage #Hack #FeeWars
Most traders using 20-100x leverage don't realise how much they're leaking in fees every month.

We ran the numbers across Bybit, Binance and BYDFi and the difference between the most and least expensive platform adds up to $2,000 in savings every single month. That's not trading profits — that's just money you're giving away unnecessarily in fees.

If you're trading at any serious volume, switching platform alone could be the most profitable move you make this year.

The exact calculations: https://trading365.org/guides/the-bybit-weex-bydfi-fee-hack-how-to-save-2000-monthly-on-20-100x-leverage
#Hack #FeeWars
📊 Dune Analyzes LayerZero OApp Security: 47% Rely on Minimum 1-of-1 DVN Setup According to Dune, following the KelpDAO hack, it analyzed the DVN security configurations of active OApps on LayerZero over the past 90 days. The #data reveals that among approximately 2,665 unique OApp contracts: - 47% run on the 1-of-1 DVN security floor - 45% #use 2-of-2 - Only about 5% #use 3-of-3 or higher configurations Notably, KelpDAO's rsETH falls into the lowest 1-of-1 security category. #hack #crypto
📊 Dune Analyzes LayerZero OApp Security: 47% Rely on Minimum 1-of-1 DVN Setup

According to Dune, following the KelpDAO hack, it analyzed the DVN security configurations of active OApps on LayerZero over the past 90 days. The #data reveals that among approximately 2,665 unique OApp contracts:

- 47% run on the 1-of-1 DVN security floor

- 45% #use 2-of-2

- Only about 5% #use 3-of-3 or higher configurations

Notably, KelpDAO's rsETH falls into the lowest 1-of-1 security category. #hack

#crypto
Рынок DeFi снова показывает свою тёмную сторону…✅️😳 За последние 3 недели из системы уже “выпало” более $600M ликвидности. И это не просто цифры — это деньги, которые исчезли из доверия. Последний удар — эксплойт Kelp DAO на $292M. После него рынок начал ускоренно терять капитал. TVL уже упал до $82.4B (это почти -25% от уровня начала 2026 года) Но самое интересное — это не сам обвал… а то, КАК он происходит. Ликвидность уходит неравномерно: лендинги страдают сильнее всего (-13%), и это обычно сигнал, что рынок “разматывается” дальше. Сейчас это не паника… но уже и не спокойная коррекция. Такие фазы обычно выглядят тихо — пока не становится поздно. 🔥 Вопрос не в том “упадёт ли дальше” Вопрос — кто уже внутри системы, когда это ускорится #DeFi #crypto #hack #TVL
Рынок DeFi снова показывает свою тёмную сторону…✅️😳
За последние 3 недели из системы уже “выпало” более $600M ликвидности.
И это не просто цифры — это деньги, которые исчезли из доверия.
Последний удар — эксплойт Kelp DAO на $292M.
После него рынок начал ускоренно терять капитал.
TVL уже упал до $82.4B
(это почти -25% от уровня начала 2026 года)
Но самое интересное — это не сам обвал…
а то, КАК он происходит.
Ликвидность уходит неравномерно:
лендинги страдают сильнее всего (-13%),
и это обычно сигнал, что рынок “разматывается” дальше.
Сейчас это не паника…
но уже и не спокойная коррекция.
Такие фазы обычно выглядят тихо —
пока не становится поздно.
🔥 Вопрос не в том “упадёт ли дальше”
Вопрос — кто уже внутри системы, когда это ускорится
#DeFi #crypto #hack #TVL
🥷 #BTC #Bitcoin Dominance returns to 60%, its high level mark for 2026, as the #DeFi market implodes after another hack by North Korea. #hack #crypto $BTC
🥷 #BTC #Bitcoin Dominance returns to 60%, its high level mark for 2026, as the #DeFi market implodes after another hack by North Korea. #hack

#crypto
$BTC
$292 milhões roubados da Kelp DAO — o maior hack de 2026 Um atacante drenou 116.500 rsETH da bridge da Kelp DAO, cerca de 18% do supply em circulação, desencadeando congelamentos de emergência no Aave, SparkLend, Fluid e Upshift. Isto levantou uma questão séria: o DeFi está preparado para escalar com segurança? A comunidade já fala em "o pior ano para hacks". Segurança primeiro, sempre. 🔐 Se o DeFi foi hackeado por $292M esta semana, ainda confiam nos protocolos descentralizados? O hack da Kelp DAO abalou a confiança de muita gente. Mas a tecnologia blockchain continua intacta — o problema foi a bridge. DeFi está morto ou é apenas mais um obstáculo no caminho para a maturidade? Comentem ⬇️ #DeFi #Hack #KelpDAO #CryptoSecurity
$292 milhões roubados da Kelp DAO — o maior hack de 2026
Um atacante drenou 116.500 rsETH da bridge da Kelp DAO, cerca de 18% do supply em circulação, desencadeando congelamentos de emergência no Aave, SparkLend, Fluid e Upshift. Isto levantou uma questão séria: o DeFi está preparado para escalar com segurança? A comunidade já fala em "o pior ano para hacks". Segurança primeiro, sempre. 🔐

Se o DeFi foi hackeado por $292M esta semana, ainda confiam nos protocolos descentralizados?
O hack da Kelp DAO abalou a confiança de muita gente. Mas a tecnologia blockchain continua intacta — o problema foi a bridge. DeFi está morto ou é apenas mais um obstáculo no caminho para a maturidade? Comentem ⬇️
#DeFi #Hack #KelpDAO #CryptoSecurity
📊 Aave in Crisis: rsETH Exploit Sparks $7B TVL Collapse and -15% Drop Amid Inflow Surge. In total, cumulative inflows across exchanges exceeded 355,000 AAVE, or approximately $32M. Against this backdrop, the $AAVE token experienced a sharp correction of around -15% on the day, reflecting both system-wide stress among investors and a clear deterioration in sentiment toward the protocol. #hack #crypto
📊 Aave in Crisis: rsETH Exploit Sparks $7B TVL Collapse and -15% Drop Amid Inflow Surge. In total, cumulative inflows across exchanges exceeded 355,000 AAVE, or approximately $32M. Against this backdrop, the $AAVE token experienced a sharp correction of around -15% on the day, reflecting both system-wide stress among investors and a clear deterioration in sentiment toward the protocol. #hack

#crypto
·
--
ສັນຍານໝີ
#AAVE mất 10 tỷ Dollar giá trị TVL chỉ trong 48h. Vụ hack giao thức KelpDAO đã gây ảnh hưởng đến một trong những mảnh ghép DeFi quan trọng nhất thế giới. $AAVE #Hack
#AAVE mất 10 tỷ Dollar giá trị TVL chỉ trong 48h.

Vụ hack giao thức KelpDAO đã gây ảnh hưởng đến một trong những mảnh ghép DeFi quan trọng nhất thế giới.

$AAVE #Hack
#Hack 🚨 $290 million in losses: LayerZero accuses Kelp DAO of security breaches New details of the Kelp DAO hack, which was carried out by the North Korean group Lazarus (TraderTraitor). LayerZero published a report, clearly indicating the cause: human error and dangerous configuration. 🔍 How it happened (Technical "multi-stepper"): 1. RPC node poisoning: Hackers replaced the software on two nodes, forcing them to "selectively lie". The nodes issued fake data only to LayerZero verifier requests, remaining "honest" for others to avoid monitoring. 2. DDoS attack: To disable healthy external nodes, Lazarus launched a DDoS. The system automatically failed over to the same servers "poisoned" by hackers. 3. Withdrawal: After receiving confirmation of the fake transaction, the Kelp bridge released 116,500 rsETH to the attackers. The malware then self-destructed. ⚠️ The main mistake: "1-of-1" LayerZero claims that the Kelp DAO ignored the recommendations and used a 1-of-1 DVN configuration. • How it was: Only one verifier (LayerZero Labs) confirmed transactions. It was compromised through the infrastructure - and the protection collapsed. • How it should have been: A decentralized network of verifiers (Multi-DVN). Even if one verifier "went crazy", the others would not have allowed the theft to be confirmed. 🛑 Market implications: • LayerZero Labs announced that they will no longer support applications with a "1-of-1" configuration. This is a forced migration to multi-verification for the entire protocol. • Protocol Security: This is not a bug in the LayerZero code. This is a configuration error in a specific integrator (Kelp). Other applications (OFT tokens) are safe. • Lazarus Group is at the peak of activity: in the last 18 days they have withdrawn over $575 million from DeFi (Drift + Kelp), each time using new methods.
#Hack
🚨 $290 million in losses: LayerZero accuses Kelp DAO of security breaches

New details of the Kelp DAO hack, which was carried out by the North Korean group Lazarus (TraderTraitor). LayerZero published a report, clearly indicating the cause: human error and dangerous configuration.

🔍 How it happened (Technical "multi-stepper"):
1. RPC node poisoning: Hackers replaced the software on two nodes, forcing them to "selectively lie". The nodes issued fake data only to LayerZero verifier requests, remaining "honest" for others to avoid monitoring.
2. DDoS attack: To disable healthy external nodes, Lazarus launched a DDoS. The system automatically failed over to the same servers "poisoned" by hackers.
3. Withdrawal: After receiving confirmation of the fake transaction, the Kelp bridge released 116,500 rsETH to the attackers. The malware then self-destructed.

⚠️ The main mistake: "1-of-1"
LayerZero claims that the Kelp DAO ignored the recommendations and used a 1-of-1 DVN configuration.
• How it was: Only one verifier (LayerZero Labs) confirmed transactions. It was compromised through the infrastructure - and the protection collapsed.
• How it should have been: A decentralized network of verifiers (Multi-DVN). Even if one verifier "went crazy", the others would not have allowed the theft to be confirmed.

🛑 Market implications:
• LayerZero Labs announced that they will no longer support applications with a "1-of-1" configuration. This is a forced migration to multi-verification for the entire protocol.
• Protocol Security: This is not a bug in the LayerZero code. This is a configuration error in a specific integrator (Kelp). Other applications (OFT tokens) are safe.
• Lazarus Group is at the peak of activity: in the last 18 days they have withdrawn over $575 million from DeFi (Drift + Kelp), each time using new methods.
VoLoDyMyR7:
Цікава інформація 🤝👍🔥
{alpha}(560x0e63b9c287e32a05e6b9ab8ee8df88a2760225a9) KelpDAO hack rattles the DeFi tape, and $GUN $SUPER $PIEVERSE are now watching for spillover risk ⚠️ A reported $290M exploit, possibly tied to Lazarus-style tactics, is the kind of event that makes liquidity pull back fast. With no other cross-chain assets affected so far, the market may price this less as a broader contagion and more as a targeted security shock, but whales will stay defensive until the full attack path is confirmed. Not financial advice. Manage your risk and protect your capital. #CryptoNews #DeFi #Hack #Altcoins #Web3 ⚡ {future}(SUPERUSDT) {future}(GUNUSDT)
KelpDAO hack rattles the DeFi tape, and $GUN $SUPER $PIEVERSE are now watching for spillover risk ⚠️

A reported $290M exploit, possibly tied to Lazarus-style tactics, is the kind of event that makes liquidity pull back fast. With no other cross-chain assets affected so far, the market may price this less as a broader contagion and more as a targeted security shock, but whales will stay defensive until the full attack path is confirmed.

Not financial advice. Manage your risk and protect your capital.

#CryptoNews #DeFi #Hack #Altcoins #Web3

🚨 Aave in Crisis: $6.6 Billion Deposits Vanish 🚨 After the Kelp DAO hack, Aave is left with $196 Million BAD DEBT 😱 💥 Impact: 🔴 TVL dropped -$6.6 Billion 🔴 AAVE price crashed to $92 (-16%) 🔴 stkAAVE holders might be forced to cover losses if reserves run out ⚠️ This exposes major structural risks in DeFi. Extreme caution advised! 🛑 $AAVE #KelpDAO #DeFi #Hack #CryptoNews
🚨 Aave in Crisis: $6.6 Billion Deposits Vanish 🚨

After the Kelp DAO hack, Aave is left with $196 Million BAD DEBT 😱

💥 Impact:
🔴 TVL dropped -$6.6 Billion
🔴 AAVE price crashed to $92 (-16%)
🔴 stkAAVE holders might be forced to cover losses if reserves run out ⚠️

This exposes major structural risks in DeFi. Extreme caution advised! 🛑

$AAVE #KelpDAO #DeFi #Hack #CryptoNews
🐳 The OTC whale who previously bought 163,405 $ETH ($440M) and 4,000 $cbBTC ($296M) has withdrawn 98,032 $wstETH ($272M) and 3,000 $cbBTC ($221.6M) from Aave. Affected by the KelpDAO rsETH bridge exploit, he was unable to withdraw $ETH, so he directly swapped 7,438 aEthWETH ($16.83M) into 1,930 $stETH and 5,272 $ETH, taking a loss of 237 $ETH ($540K). He still has 10,000 $ETH ($22.8M) remaining on Aave. #hack #crypto
🐳 The OTC whale who previously bought 163,405 $ETH ($440M) and 4,000 $cbBTC ($296M) has withdrawn 98,032 $wstETH ($272M) and 3,000 $cbBTC ($221.6M) from Aave. Affected by the KelpDAO rsETH bridge exploit, he was unable to withdraw $ETH, so he directly swapped 7,438 aEthWETH ($16.83M) into 1,930 $stETH and 5,272 $ETH, taking a loss of 237 $ETH ($540K). He still has 10,000 $ETH ($22.8M) remaining on Aave. #hack

#crypto
🕵️ DeFiLlama Co-founder 0xngmi on Kelp DAO rsETH Hack, 3 Potential Paths: - Socialize losses across all users 18.5% haircut → ~$216M bad debt on Aave. Umbrella covers $55M, Aave treasury covers $85M, leaving $76M gap (can be filled by borrowing or selling ~$51M $AAVE from treasury). - Rug rsETH holders on L2s Creates ~$341M bad debt on Aave (mainly Arbitrum, Mantle, Base). No Umbrella coverage, Aave would have to absorb everything. - Compensate using pre-hack snapshot Very difficult due to heavy fund flows and pooled liquidity. Even after Umbrella, remaining loss would still be ~$91M. #hack #crypto
🕵️ DeFiLlama Co-founder 0xngmi on Kelp DAO rsETH Hack, 3 Potential Paths:

- Socialize losses across all users

18.5% haircut → ~$216M bad debt on Aave. Umbrella covers $55M, Aave treasury covers $85M, leaving $76M gap (can be filled by borrowing or selling ~$51M $AAVE from treasury). - Rug rsETH holders on L2s

Creates ~$341M bad debt on Aave (mainly Arbitrum, Mantle, Base). No Umbrella coverage, Aave would have to absorb everything. - Compensate using pre-hack snapshot

Very difficult due to heavy fund flows and pooled liquidity. Even after Umbrella, remaining loss would still be ~$91M. #hack

#crypto
🤔 OneKey Founder Yishi on Handling the KelpDAO Hack 1. Best case: negotiate with the hacker and offer a 10-15% bounty. 2. If talks fail, let the LayerZero ecosystem fund cover most of the loss. 3. KelpDAO is the weakest. compensate with tokens + future revenue, or sell the whole project to L0 or BMNR. 4. Aave’s Umbrella and stkAAVE serve as the final backstop, but WETH depositors must not take any haircut, otherwise it would trigger repricing across Morpho, Spark, Fluid, Euler, blacklist the LRT sector, and set #DeFi back by years. 5. He believes Aave can survive this. #hack #crypto
🤔 OneKey Founder Yishi on Handling the KelpDAO Hack

1. Best case: negotiate with the hacker and offer a 10-15% bounty. 2. If talks fail, let the LayerZero ecosystem fund cover most of the loss. 3. KelpDAO is the weakest. compensate with tokens + future revenue, or sell the whole project to L0 or BMNR. 4. Aave’s Umbrella and stkAAVE serve as the final backstop, but WETH depositors must not take any haircut, otherwise it would trigger repricing across Morpho, Spark, Fluid, Euler, blacklist the LRT sector, and set #DeFi back by years. 5. He believes Aave can survive this. #hack

#crypto
ບົດຄວາມ
AAVE: someone stole $293 million with $250 in gas feesYesterday, someone stole $293 million with $250 in gas fees. No zero-day vulnerability. No broken code. Just a mischecked box in a configuration file. Let me explain. THE TIMELINE - April 18, 2026, 11:05 AM UTC. An anonymous wallet receives 0.1 ETH from Tornado Cash. Cost: ~$250. For 6 hours, nothing happens. Then at 5:35 PM, this wallet executes ONE SINGLE function call on the Kelp DAO contract. And 116,500 rsETH appear out of thin air. Value: $293 million. 🔓 THE VULNERABILITY (explained simply) Imagine a vault with 3 locks. Standard security practice says: "you need 2 out of 3 keys to open it." But Kelp DAO configured their LayerZero bridge differently: "1 key is enough." That "key" was a DVN (Decentraized Verifier Network). ONE SINGLE validator. Exact configuration: → requiredDVNCount: 1 → optionalDVNCount: 0 The attacker compromised this single node, forged a fake cross-chain message saying "send 116k rsETH to this address," and the contract obeyed. This wasn't a code bug, it was a deployment misconfiguration. Audits check code. Not always the config. THE HEIST (in 46 minutes) 5:35 PM → Exploit: mint of 116,500 unbacked rsETH 5:36-5:42 PM → Distribution to 7 intermediate wallets: - 53,000 rsETH → 0x1f4c1c - 30,000 rsETH → 0xeba786 - 10,000 rsETH → 0xcbb24a - 8,000 rsETH → 0x1b748b - 6,000 rsETH → 0xbb6a60 - 5,000 rsETH → 0x8d11ae - 4,500 rsETH → 0xe9e2f4 5:45-6:00 PM → Deposited as collateral on AAVE V3, Compound V3, AAVE Arbitrum 6:00 PM+ → Borrowed $236M in WETH against this "collateral" 6:15 PM → Consolidated to a single wallet The problem? These rsETH have ZERO real value. They're worthless. But the lending protocol oracles couldn't know that. THE ATTACKER'S ADDRESSES I traced the entire flow on-chain: Main wallet (exploiter): 0x8B1b6c → Funded via Tornado Cash 0.1 ETH Pool → Executed the fraudulent lzReceive() call Profit consolidation wallet: ETH Millionaire 0x5d391: app.nansen.ai/profiler?addre… → Labeled "ETH Millionaire" by #NansenAI → Received $163M+ in borrowed ETH → Likely being mixed through Tornado Cash as we speak Exploit transaction: 0x1ae232da212c45f35c1525f851e4c41d529bf18af862d9ce9fd40bf709db4222 THE IMPACT ON AAVE $AAVE was NOT directly hacked but the protocol is now sitting on a $236M bad debt hole. The rsETH used as collateral is now worth zero. The WETH loans will never be repaid. The positions are unliquidatable. The numbers in 24h: - $AAVE price: -22% over 7 days ($115 → $90) - TVL: -16.78% ($21.96B) - Exchange inflows: +$22.6M (16x normal average) - Smart Trader outflows: -$248k - Top PnL wallets outflows: -$2.4M Emergency measures: 🔒 rsETH/wrsETH markets frozen on all V3/V4 instances 🔒 WETH frozen on Core, Prime, Arbitrum, Base, Mantle, Linea WHO'S GOING TO PAY? You, if you staked $aETHWETH on AAVE. The Umbrella module will automatically take a portion of your stake to cover the losses. How it works: 1. UmbrellaCore monitors bad debt on-chain 2. When threshold is exceeded → slash() is called automatically 3. Pro-rata burn of vault shares 4. No governance vote required, it's automatic Withdrawal cooldown: 20 days. This isn't a bug. It's by design. You signed up for this in the terms. HISTORICAL COMPARISON This hack joins the podium of biggest bridge exploits: 🥇 Ronin (2022): $625M - 5/9 validator compromise 🥈 Wormhole (2022): $326M - Signature verification bug 🥉 Kelp DAO (2026): $293M - 1-of-1 DVN compromise 4️⃣ Nomad (2022): $190M - Merkle root flaw Common pattern: trust assumptions on cross-chain validators. Total bridge hacks since 2022: >$2.8 billion (~40% of all Web3 hacks). MY TAKEAWAYS 1. A code audit ≠ a config audit. Kelp's code was audited. The 1-of-1 DVN configuration apparently wasn't. 2. One validator = one point of failure. Industry standard: minimum 2-of-3. Kelp: 1-of-1. It was a ticking time bomb. 3. LRTs as collateral = systemic risk. Liquid Restaking Tokens add layers of complexity that current oracles can't evaluate in real-time. 4. DeFi remains the Wild West. $293M stolen with $250 in gas. Attacker's ROI: 586,000,000%. 🔍 TO FOLLOW THE CASE Wallet to monitor (fund consolidation): 0x5d3919f12bcc35c26eee5f8226a9bee90c257ccc The funds are likely being mixed through Tornado Cash as you read this post. This wasn't an AAVE hack, it was a hack of trust. One mischecked box. A "default" config. $293M gone. Welcome to DeFi. If this post was useful, share it. More people need to understand that DeFi security isn't just about code. And if you have $aWETH staked on AAVE... you know what to do. #Hack #CyberSecurity #OnChainAnalysis $AAVE {spot}(AAVEUSDT)

AAVE: someone stole $293 million with $250 in gas fees

Yesterday, someone stole $293 million with $250 in gas fees. No zero-day vulnerability. No broken code. Just a mischecked box in a configuration file.

Let me explain.

THE TIMELINE
- April 18, 2026, 11:05 AM UTC.
An anonymous wallet receives 0.1 ETH from Tornado Cash. Cost: ~$250.
For 6 hours, nothing happens.
Then at 5:35 PM, this wallet executes ONE SINGLE function call on the Kelp DAO contract.
And 116,500 rsETH appear out of thin air.
Value: $293 million.

🔓 THE VULNERABILITY (explained simply)
Imagine a vault with 3 locks. Standard security practice says: "you need 2 out of 3 keys to open it." But Kelp DAO configured their LayerZero bridge differently: "1 key is enough."

That "key" was a DVN (Decentraized Verifier Network). ONE SINGLE validator.

Exact configuration:
→ requiredDVNCount: 1
→ optionalDVNCount: 0
The attacker compromised this single node, forged a fake cross-chain message saying "send 116k rsETH to this address," and the contract obeyed. This wasn't a code bug, it was a deployment misconfiguration.
Audits check code. Not always the config.

THE HEIST (in 46 minutes)

5:35 PM → Exploit: mint of 116,500 unbacked rsETH

5:36-5:42 PM → Distribution to 7 intermediate wallets:
- 53,000 rsETH → 0x1f4c1c
- 30,000 rsETH → 0xeba786
- 10,000 rsETH → 0xcbb24a
- 8,000 rsETH → 0x1b748b
- 6,000 rsETH → 0xbb6a60
- 5,000 rsETH → 0x8d11ae
- 4,500 rsETH → 0xe9e2f4

5:45-6:00 PM → Deposited as collateral on AAVE V3, Compound V3, AAVE Arbitrum

6:00 PM+ → Borrowed $236M in WETH against this "collateral"

6:15 PM → Consolidated to a single wallet

The problem?
These rsETH have ZERO real value. They're worthless. But the lending protocol oracles couldn't know that.

THE ATTACKER'S ADDRESSES

I traced the entire flow on-chain:

Main wallet (exploiter): 0x8B1b6c
→ Funded via Tornado Cash 0.1 ETH Pool
→ Executed the fraudulent lzReceive() call

Profit consolidation wallet:
ETH Millionaire 0x5d391: app.nansen.ai/profiler?addre…
→ Labeled "ETH Millionaire" by #NansenAI
→ Received $163M+ in borrowed ETH
→ Likely being mixed through Tornado Cash as we speak

Exploit transaction:
0x1ae232da212c45f35c1525f851e4c41d529bf18af862d9ce9fd40bf709db4222

THE IMPACT ON AAVE

$AAVE was NOT directly hacked but the protocol is now sitting on a $236M bad debt hole.
The rsETH used as collateral is now worth zero.
The WETH loans will never be repaid.
The positions are unliquidatable.

The numbers in 24h:
- $AAVE price: -22% over 7 days ($115 → $90)
- TVL: -16.78% ($21.96B)
- Exchange inflows: +$22.6M (16x normal average)
- Smart Trader outflows: -$248k
- Top PnL wallets outflows: -$2.4M

Emergency measures:
🔒 rsETH/wrsETH markets frozen on all V3/V4 instances
🔒 WETH frozen on Core, Prime, Arbitrum, Base, Mantle, Linea

WHO'S GOING TO PAY?
You, if you staked $aETHWETH on AAVE.

The Umbrella module will automatically take a portion of your stake to cover the losses.

How it works:
1. UmbrellaCore monitors bad debt on-chain
2. When threshold is exceeded → slash() is called automatically
3. Pro-rata burn of vault shares
4. No governance vote required, it's automatic

Withdrawal cooldown: 20 days. This isn't a bug. It's by design. You signed up for this in the terms.

HISTORICAL COMPARISON

This hack joins the podium of biggest bridge exploits:

🥇 Ronin (2022): $625M - 5/9 validator compromise
🥈 Wormhole (2022): $326M - Signature verification bug
🥉 Kelp DAO (2026): $293M - 1-of-1 DVN compromise
4️⃣ Nomad (2022): $190M - Merkle root flaw

Common pattern: trust assumptions on cross-chain validators.

Total bridge hacks since 2022: >$2.8 billion (~40% of all Web3 hacks).

MY TAKEAWAYS

1. A code audit ≠ a config audit. Kelp's code was audited. The 1-of-1 DVN configuration apparently wasn't.

2. One validator = one point of failure. Industry standard: minimum 2-of-3. Kelp: 1-of-1. It was a ticking time bomb.

3. LRTs as collateral = systemic risk. Liquid Restaking Tokens add layers of complexity that current oracles can't evaluate in real-time.

4. DeFi remains the Wild West. $293M stolen with $250 in gas. Attacker's ROI: 586,000,000%.

🔍 TO FOLLOW THE CASE

Wallet to monitor (fund consolidation):
0x5d3919f12bcc35c26eee5f8226a9bee90c257ccc

The funds are likely being mixed through Tornado Cash as you read this post.

This wasn't an AAVE hack, it was a hack of trust.
One mischecked box. A "default" config. $293M gone.

Welcome to DeFi.

If this post was useful, share it. More people need to understand that DeFi security isn't just about code.

And if you have $aWETH staked on AAVE... you know what to do.

#Hack #CyberSecurity #OnChainAnalysis

$AAVE
ເຂົ້າສູ່ລະບົບເພື່ອສຳຫຼວດເນື້ອຫາເພີ່ມເຕີມ
ເຂົ້າຮ່ວມກຸ່ມຜູ້ໃຊ້ຄຣິບໂຕທົ່ວໂລກໃນ Binance Square.
⚡️ ໄດ້ຮັບຂໍ້ມູນຫຼ້າສຸດ ແລະ ທີ່ມີປະໂຫຍດກ່ຽວກັບຄຣິບໂຕ.
💬 ໄດ້ຮັບຄວາມໄວ້ວາງໃຈຈາກຕະຫຼາດແລກປ່ຽນຄຣິບໂຕທີ່ໃຫຍ່ທີ່ສຸດໃນໂລກ.
👍 ຄົ້ນຫາຂໍ້ມູນເຊີງເລິກທີ່ແທ້ຈາກນັກສ້າງທີ່ໄດ້ຮັບການຢືນຢັນ.
ອີເມວ / ເບີໂທລະສັບ