What happened?
In a single transaction an unknown attacker exploited the Kelp DAO bridge, a LayerZero‑based cross‑chain router that lets users move rsETH between Ethereum, Optimism and other L2s. The exploit emptied roughly $292 million (around ₹24 billion) of rsETH from the system. Within minutes Kelp’s devs hit the emergency stop and froze all rsETH contracts to stop further loss.
How the bridge works (in a nutshell)
Kelp’s bridge is built on LayerZero – a messaging protocol that lets smart contracts on different chains talk to each other as if they were on the same chain. When you deposit rsETH on Ethereum, the bridge locks the original tokens and mints a wrapped version on the destination chain. The reverse works the same way: burn the wrapped token, unlock the original.
Where the attack hit
The attacker targeted the bridgeRouter contract that coordinates the mint‑and‑burn process. By feeding malformed payloads to LayerZero’s endpoint, they triggered a re‑entrancy style bug that allowed them to mint rsETH on the destination chain without actually locking the underlying ETH on the source chain. In short, they created money out of thin air.
Numbers at a glance
- Total value stolen: ~$292 M (≈₹24 B)
- Chains affected: Ethereum, Optimism, Arbitrum
- Number of rsETH tokens minted illicitly: ~250,000 rsETH
- Time to pause contracts: ~5 minutes after the first alert
Why Indian users should care
Many Indian DeFi enthusiasts have been using rsETH as a low‑risk yield‑bearing asset on Polygon and Optimism because it offers higher APY than plain ETH staking. If you hold rsETH in a wallet that wasn’t directly interacting with the Kelp bridge, you’re still at risk because the contracts are now paused – you can’t withdraw, swap or bridge until Kelp releases a fix. This also raises a red flag for any Indian project that relies on LayerZero for cross‑chain messaging. A breach like this could ripple into other protocols that share the same endpoint.
What Kelp is doing now
The team announced a full audit of the bridge code, a migration plan to a new LayerZero v2 endpoint, and a compensation fund that will be funded by Kelp’s treasury and community contributors. They also opened a bounty for white‑hat hunters who can locate any remaining vulnerabilities.
TamilTech’s take
Honestly, this is a wake‑up call for everyone building on cross‑chain infrastructure. LayerZero is powerful, but it’s still young, and the security model is complex – you’re essentially trusting a third‑party relayer with your message integrity. Indian developers should start diversifying: use multi‑chain bridges, audit every external call, and keep a hot‑wallet buffer for emergency withdrawals.
What you can do right now
- Check your wallet: if you hold rsETH, look for a ‘paused’ flag on the token contract.
- Do NOT try to bridge or trade rsETH until Kelp posts a official “unpause” notice.
- Consider moving to alternative wrapped ETH solutions like wstETH or Lido’s stETH, which have separate bridge mechanisms.
- Stay tuned to Kelp’s Discord and Twitter for the latest patch notes.
Looking ahead
We expect Kelp to launch a patched bridge within the next two weeks. In the meantime, the incident will likely push other DeFi projects to re‑evaluate their reliance on a single messaging layer. For Indian investors, the lesson is clear: spread risk across multiple protocols and keep an eye on bridge health dashboards.
Stay safe, keep your private keys private, and remember – in DeFi, the only guarantee is that you’re responsible for your own security.




Comments (0)
Be the first to comment!