Edited By
David Wong

On April 22, 2026, KelpDAO's bridge was exploited, resulting in the loss of 116,500 rsETH, valued at about $292 million. The exploit involved faking a cross-chain message, bypassing LayerZero's verification mechanism. The attacker then used the stolen funds as collateral on Aave, borrowing $236 million in WETH. Aave allowed this because it listed rsETH as an acceptable asset, leading to chaos across multiple protocols.
KelpDAO's misfortunes stem from an attack that was surprisingly simple. Sources confirm that the attacker manipulated a seemingly standard feature, raising questions about the trustworthiness of bridges in decentralized finance (DeFi).
If that wasn't troubling enough, once the funds were funneled into Aave, panic ensued. SparkLend, Fluid, and Lido temporarily paused operations as the fallout from the incidents began.
"This sets a dangerous precedent for all bridges that rely on off-chain relayers," a concerned user stated. An alarming 47 attacks have already occurred in 2026, compared to 28 during the same timeframe last year.
Aaveβs total value locked (TVL) plummeted significantly, as many began to question the reliability of deposit protocols. Users are expressing their frustrations on various forums, noting that just about every aspect of the lending space is in flux.
Several comments highlight conflicting perspectives:
"It's not Aaveβs fault. They didnβt get hacked!"
"What about the bridges? Can they be trusted anymore?"
"People lose their money every day; this isn't unique."
The situation worsened when Arbitrum intervened, freezing about $71 million to recover some lost fundsβthough the majority of stolen assets remain scattered across over 20 chains.
While some users remain loyal to DeFi platformsβciting long-term stability and returnsβothers are feeling the urge to shift back to centralized exchanges (CEXs). A frequent sentiment echoed among the community seems to veer toward frustration, especially given the realization that even "fully audited" protocols may not be completely foolproof.
"You can set an investment in a fully audited protocol and still end up rekt. Thatβs where we are right now," lamented one user.
πΊ $292 million lost in KelpDAO hack, stressing vulnerability of bridges.
π½ Aaveβs TVL decreased dramatically as concern mounted.
β "Couldnβt care less; DeFi might be overrated now!" - Popular sentiment among detractors.
As discussions continue, can the DeFi community find a way to bolster trust in its infrastructure, or is this just the beginning of a long road of skepticism?
A growing coalition of users is now more apprehensive than ever about the safety of their investments, leaving many to wonder whether it's time to retreat from DeFi altogether.
Thereβs a strong chance that the KelpDAO exploit will accelerate calls for regulatory measures targeting decentralized finance platforms. Experts estimate around 60% of users could lean toward more secure centralized exchanges (CEXs) in the coming months, especially as trust in bridges and protocols erodes. With the mounting pressure, DeFi platforms will likely feel compelled to overhaul their security measures, leading to an increase in insurance options for investments and a re-evaluation of how assets are verified across protocols. If the trend continues, we may see a consolidation among DeFi projects as smaller players struggle to maintain credibility amidst heightened skepticism.
A striking parallel can be drawn between the current DeFi chaos and the era of the 2008 financial crisis, when trust in traditional banking evaporated almost overnight. Just as mortgage-backed securities were suspected of harboring flaws, todayβs digital assets and bridges are under scrutiny for their vulnerabilities. In both instances, reliance on seemingly sound architecture led to widespread chaos when the system was tested. The crypto world's shift mirrors past financial practices, where shortcuts allowed for growth at the expense of safetyβreminding people that technological advancement doesn't exempt them from the responsibility of due diligence.