The attacker of the Kelp DAO exploit has moved approximately $175 million in Ether across multiple transactions to newly created addresses, likely to launder the stolen funds. This follows a significant exploit where around $290 million was drained from Kelp DAO's LayerZero-powered bridge.
Key points
Attacker moved 75,700 Ether worth $175 million
Total stolen from Kelp DAO was approximately $290 million
LayerZero warned against Kelp DAO's single verifier path setup
The attacker behind the roughly $290 million Kelp DAO exploit began moving tens of thousands of Ether to newly created blockchain addresses on Tuesday, in an apparent effort to start laundering the stolen funds.
The wallet tagged by Arkham as linked to the Kelp DAO exploit moved about 75,700 Ether (ETH) worth roughly $175 million across three transactions on Tuesday, including a 25,000 ETH transfer to one newly created address and transfers of 50,700 ETH and 0.7 ETH to another.
Blockchain investigator ZachXBT wrote in a Tuesday Telegram post that addresses tied to the exploit had begun moving funds through THORChain and Umbra. He flagged three THORChain transactions totaling about $1.5 million and a separate $78,000 transfer through Umbra.
LayerZero said Kelp DAO’s 1/1 decentralized verifier network (DVN) setup created a single point of failure by relying on a single verifier path for cross-chain messages. LayerZero said it had previously advised against that configuration.
Fallout spreads across DeFi
The transfers came hours after Arbitrum said its 12-member security council had taken emergency action to freeze 30,766 ETH tied to the exploit and move the funds into an “intermediary frozen wallet” accessible only through Arbitrum governance.
Kelp DAO Attacker-tagged wallet, latest transactions. Source: Arkham
The exploit also hit other DeFi protocols, including Aave, where the attacker used the against the protocol. Early estimates put the hole at about $195 million, but Aave’s April 20 incident report later : roughly $123.7 million in bad debt under one scenario and about $230.1 million under another.
Q&A
How much Ether was moved by the Kelp DAO attacker?
The Kelp DAO attacker moved about 75,700 Ether, worth roughly $175 million.
What was the total amount stolen in the Kelp DAO exploit?
The total amount stolen in the Kelp DAO exploit was approximately $290 million.
What vulnerabilities did LayerZero identify in Kelp DAO's setup?
LayerZero identified that Kelp DAO's decentralized verifier network created a single point of failure by relying on a single verifier path for cross-chain messages.
Bank of Korea's New Governor Prioritizes CBDCs Over Stablecoins in First Policy Address
Bank of Korea's new Governor Shin Hyun-song prioritizes central bank digital currencies and bank-issued deposit tokens in his first policy address, omitting stablecoins. This comes amid ongoing legislative debates on stablecoin regulation in South Korea.
The transfers suggest the attackers had begun moving funds through non-custodial protocols that can complicate tracing and recovery. THORChain does not require traditional Know Your Customer checks.
During the $1.4 billion Bybit hack, attackers converted about 83% of the stolen Ether into Bitcoin (BTC), with 72% of the funds moving through THORChain, according to Bybit CEO Ben Zhou. Zhou said at the time that 77% of the stolen funds were still traceable, meaning the flows were not fully untraceable.
Aave unfreezes Ethereum V3 market as borrow rates spike
On Tuesday, Aave said it had unfrozen Wrapped Ether (WETH) reserves on the Ethereum Core V3 market, enabling users to supply WETH to the V3 lending protocol once again. However, WETH reserves across Ethereum Prime, Arbitrum, Base, Mantle and Linea remain frozen.
Meanwhile, the thinning liquidity saw Aave’s borrowing rates for USDt (USDT) rise from 3% to 14%, marking the highest figures since December 2024, wrote Julio Moreno, the head of research at analytics platform CryptoQuant, in a Monday X post.
Fears over a potential contagion caused significant outflows from Aave, as its total value locked (TVL) fell by about $10 billion since the exploit to $16.4 billion as of Tuesday, DeFiLlama data shows.