The biggest DeFi heist of 2026, hackers easily took advantage of Aave
Author: Xiao Bing, Shenchao TechFlow
On the evening of April 18 at 17:35 (UTC), a wallet that had laundered money through Tornado Cash sent a cross-chain message to the LayerZero EndpointV2 contract.
The message's meaning was simple: a user on a certain chain wanted to transfer rsETH back to the Ethereum mainnet. LayerZero faithfully conveyed the instruction according to the protocol design. The bridging contract deployed by Kelp DAO on the mainnet also executed the release faithfully as designed.
116,500 rsETH, worth approximately $292 million at the time, was transferred in a single transaction to an address controlled by the attacker.
The problem is that no one on the other chain had ever deposited this rsETH. This "cross-chain request" was fabricated out of thin air; LayerZero believed it, and Kelp's bridge believed it.
Forty-six minutes later, Kelp's emergency multi-signature finally hit the pause button. By this time, the attacker had already completed the latter half of the action, using the stolen, essentially uncollateralized rsETH to collateralize in Aave V3, borrowing approximately $236 million worth of wETH.
This is the largest DeFi theft of 2026 so far, surpassing the Drift protocol, which was attacked by North Korean hackers on April 1 by several million dollars, but what truly sends chills down the spine of the industry is not just the amount.
How the Attack Happened: Three Bets from 17:35 to 18:28
Let's restore the timeline.
17:35 UTC, the first success. The attacker called the lzReceive function on the LayerZero EndpointV2 contract, and a wallet funded by Tornado Cash sent a fabricated cross-chain data packet to Kelp's bridging contract. The contract verification passed, and 116,500 rsETH was released to the attacker's address. A single transaction. Clean.
18:21 UTC, Kelp's emergency pause multi-signature froze the core rsETH contracts on the mainnet and multiple L2s. 46 minutes after the attack occurred.
18:26 and 18:28 UTC, the attacker initiated two more attempts, each time attempting to withdraw 40,000 rsETH (approximately $10 million) with a LayerZero data packet. Both were reverted; the contract had already been frozen, but the attacker was clearly still trying to siphon off the remaining liquidity.
From the first success to Kelp's public statement, nearly three hours elapsed.
Kelp's first X post was not sent until 20:10 UTC, and the wording was very restrained: suspicious cross-chain activity involving rsETH was detected, the rsETH contracts on the mainnet and multiple L2s had been paused, and they were collaborating with LayerZero, Unichain, auditors, and external security experts for root cause analysis.
However, earlier than the official statement, ZachXBT, an on-chain detective, raised the alarm in his Telegram channel before 3 PM Eastern Time, listing six wallet addresses related to the theft and pointing out that the attack wallet had prepared funds through Tornado Cash before starting its actions. He did not name Kelp DAO, but on-chain analysts connected the addresses in just a few hours.
This was a **premeditated operation executed
You may also like

Morning Report | OpenAI has submitted an S-1 registration statement draft to the U.S. SEC; Morpho completes $175 million financing

Galaxy Deep Research Report: How Hyperliquid's HIP-4 Upgrade Changes the Landscape of Prediction Markets?

Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI

Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention

Every exchange is a "Universal Exchange."

The counterattack of traditional finance: Alliance chains are quietly reviving

Pantera Capital Partner: How Tokenization is Restructuring the Private Equity and Early Investment Ecosystem?

Mastercard Launches Agent Pay for AI, Plans to Record AI Agent Payment Authorizations on Polygon
Mastercard launched Agent Pay for AI, a new payment protocol designed to help AI agents make small payments such as pay-per-use access to data and APIs. The system plans to record human-granted AI agent permissions on Polygon, focusing on verifiable authorization, identity, and payment controls.

Curve Deploys Llamalend v2 on Optimism With 250,000 OP Incentives
Curve launched Llamalend v2 on Optimism with 250,000 OP incentives from the Optimism Foundation. The upgrade expands Llamalend beyond its earlier crvUSD-focused model, adding broader collateral support, LlamaRisk market reviews, and the ability to use Curve LP tokens as collateral.

Raydium Old Liquidity Pool Reportedly Exploited, With $1.34 Million Moved to Ethereum and Tornado Cash
An old Raydium liquidity pool was reportedly exploited for around $1.34 million in USDC, RAY, and wSOL, with the stolen funds bridged to Ethereum and deposited into Tornado Cash. The incident highlights the tail risks of legacy DeFi pools, old contracts, and cross-chain fund laundering paths.

Kalshi Executive Challenges “SBF Backed AI Unicorns” Narrative, Says Leopold Aschenbrenner Was Key Figure
Kalshi executive John Wang questioned the “SBF backed AI unicorns” narrative, saying Leopold Aschenbrenner was the key figure behind major AI investment decisions.

New York Proposes Stricter Stablecoin Issuer Rules Aligned With Federal GENIUS Act
NYDFS proposed stricter stablecoin issuer rules aligned with the GENIUS Act, covering reserves, custody, redemption timelines, audits, and capital buffers.

CryptoQuant Says Bitcoin Profitable Supply Is Near 45% Pressure Zone as On-Chain Data Points to Market Repricing
CryptoQuant said Bitcoin’s profitable supply is nearing the 45% pressure zone, signaling rising market stress, unrealized losses, and a possible on-chain repricing phase.

Bitcoin Falls Below 200-Week Moving Average as On-Chain Data Shows Over Half of Supply in Loss
Bitcoin dropped below its 200-week moving average as on-chain data showed over 50% of circulating supply is now in loss, signaling rising market stress.

CFTC Reportedly Plans New Prediction Market Rules Focused on Manipulation Risk and Public Interest Review
The CFTC is reportedly preparing new prediction market rules focused on manipulation risk, public interest review, and retail trader protections.

Meet the new WEEX trial fund—your gateway to greater profits

WEEX Labs Lands at Dutch Blockchain Week: A Disruptive Crypto × AI Conversation Sets Sail in Amsterdam

SK Hynix Reportedly Plans U.S. ADR Listing as Early as August, With SEC Approval Possible in Late June
SK Hynix may pursue a U.S. ADR listing as early as August, with SEC approval reportedly possible in late June amid strong AI chip supply chain demand.
