THE LATEST CRYPTO NEWS

User Models

Active Filters
# kelpdao exploit
#eth #crypto hacks #defi exploits #cryptocurrency market news #ethusdt #1inch #weth #wbtc #defi platform #drift protocol exploit #kelpdao exploit

Another multi-million-dollar attack has hit the DeFi sector after liquidity provider and market maker TrustedVolumes fell victim to a smart contract exploit on Thursday night. Related Reading: Solana Eyes New Leg Up After Triangle Breakout – Is $96 The Next Stop? TrustedVolumes Hit By $6.7M Hack On Thursday, DeFi platform TrustedVolumes, one of 1inch liquidity providers and market makers, suffered a new exploit that drained millions of dollars in multiple assets from the project. According to reports from blockchain security firms PeckShield and Blockaid, the attacker stole approximately $6 million in Wrapped Ethereum (WETH), Wrapped Bitcoin (WBTC), USDT, and USDT after exploiting a vulnerability in the protocol’s core signature validation logic, which allowed them to bypass authorization checks and forge trading orders. Notably, the hacker quickly exchanged all assets for 2.513 ETH on a Decentralized Exchange (DEX) and distributed them across three addresses. In an X post, TrustedVolumes confirmed the incident, sharing the addresses currently holding the stolen funds and updating the estimated loss to roughly $6.7 million. The vulnerability was a TrustedVolumes-controlled custom RFQ (request for quote) swap proxy. Crypto researcher Humphrey explained that “the Custom RFQ Swap Proxy contract contains a function designed to manage the ‘authorized order signer’ whitelist. Such whitelist mechanisms are common in DeFi—only addresses on the whitelist can issue valid transaction instructions on behalf of the protocol.” However, he noted that “this registration function is public and lacks any permission modifiers.” As a result, the attacker exploited this public function within the contract, registering themselves as an authorized order signer. “Since any external address can call this function, it is equivalent to giving everyone the ability to make a copy of the safe’s key,” the researcher continued. Same Hacker, Different Attack The online reports revealed that the attacker was the same hacker responsible for the $5 million 1inch Fusion V1 Settlement contract exploit in March 2025, which TrustedVolumes was the primary victim. Humprey highlighted that while the same individual carried out both attacks, they were significantly different on a technical level. According to the post, the 2025 vulnerability involved low-level EVM memory manipulation in the 1inch Fusion V1 Settlement contract. At the time, the hacker “proactively initiated on-chain negotiations,” offering to return the stolen assets for a white hat bounty. The DeFi platform accepted the proposal, and most of the funds were safely returned. Now, TrustedVolumes affirmed that it is “open to constructive communication regarding a bug bounty and a mutually acceptable resolution.” Decentralized exchange aggregator 1inch clarified that there was no impact on its systems, infrastructure, or user funds, explaining that “TrustedVolumes operate independently as a liquidity provider, used by multiple protocols across the industry, and are not exclusive to 1inch.” DeFi Exploits See Historic Surge This attack follows a wave of exploits that has shaken the DeFi sector over the past month. Last week, PeckShield revealed that the crypto space saw 40 major hacks in April, which drained approximately $647 million. Related Reading: $150M Crypto Ponzi Crumbles: $41.5M Frozen In DSJ Exchange Collapse This figure represents a 1,140% Month-over-Month (MoM) increase from March’s $52.2 million. It also represents a 292% surge from the $165 million the DeFi sector lost during the first quarter of 2026. Notably, the top two incidents of the month, Drift Protocol’s $285 million and KelpDAO’s $290 million exploits, accounted for 91% of the funds lost last month. In addition, they now rank among the Top 10 hacks since 2021. Featured Image from Unsplash.com, Chart from TradingView.com

#crypto #crypto market #lido #cryptocurrency #crypto news #breaking news ticker #lido dao news #aave (aave) #aave news #rseth #kelpdao #kelpdao exploit

KelpDAO’s liquid restaking token, rsETH, has become the center of a major DeFi recovery effort after a hack estimated at roughly $290 million. The latest development came on Thursday, when Lido Finance unveiled a proposal aimed at supporting Aave’s (AAVE) coordinated response to the rsETH shortfall.  Lido Joins rsETH Recovery Effort The Lido plan was submitted to Aave’s Research Forum following this week’s Kelp incident involving the rsETH LayerZero bridge exploit.  While the exploit’s details were still unfolding, Aave moved quickly to organize a larger, ecosystem-wide effort—“DeFi United”—with the goal of making affected users whole after the April 18 bridge incident left rsETH underbacked and, in turn, put funds at risk across multiple lending markets. Aave posted on social media platform X (formerly Twitter) that “multiple strong indicative commitments” had already been lined up, and that Lido Finance was the first public participant.  Related Reading: Bitcoin Nears $80,000: Two Scenarios That May Decide Q2—Bulls Or Bears? The proposal itself authorizes a one-time, capped contribution of up to 2,500 stETH—roughly $6 million at the time of reporting. Importantly, Aave framed this as part of a fully funded recovery package rather than a piecemeal attempt to patch only part of the damage.  The structure is meant to limit broader spillover and allow an orderly resolution for users impacted by the rsETH deficit. The conditions attached to Lido’s contribution are strict.  Lido Finance’s funds would only be deployed if the relief vehicle is large enough to cover the entire deficit—specifically, not a partial fix that still leaves users exposed.  The total shortfall is described as exceeding 100,000 ETH. If any funds remain unused, they would be returned to Lido’s treasury. And the money can only be used to address the rsETH shortfall itself. Market-Wide TVL Losses Lido’s interest in this outcome is closely tied to its own product exposure. Lido offers an EarnETH vault that has direct exposure to rsETH. Without coordinated support, losses for users in that vault could reach approximately 9,000 ETH. Aave also moved to limit further risk while recovery planning progressed. Earlier Thursday, it updated that rsETH reserves were paused across multiple Ethereum and rollup environments, including Ethereum Core, Arbitrum, Base, Mantle, and Linea.  Related Reading: 4-Figure XRP: How High Will The Price Be If Ripple Captures 50% Of SWIFT? The broader market reaction has been severe. Since the heist news first emerged on Saturday, Aave has reportedly recorded around $9 billion in net outflows as of April 21. Total value locked on the platform fell by more than a third, dropping to about 17.5 billion.  That figure has since declined further, reaching approximately 14.3 billion at the time of this writing. The damage extended beyond Aave as well: according to DefiLlama data, across all decentralized lending protocols, TVL fell by roughly $13 billion within 48 hours after the exploit. Featured image from OpenArt, chart from TradingView.com 

#layerzero #arbitrum #arb #cryptocurrency market news #kelpdao #kelpdao exploit

Arbitrum’s Security Council has frozen 30,766 ETH tied to the KelpDAO exploit, moving the funds out of an address on Arbitrum One and into an intermediary wallet that now requires further governance action to unlock. At roughly $71 million, the move was large enough on its own. What made it more consequential was the method: a crypto governance body stepping in directly to override the normal finality of chain-held funds. In its statement, Arbitrum said: “The Arbitrum Security Council has taken emergency action to freeze the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. The Security Council acted with input from law enforcement as to the exploiter’s identity, and, at all times, weighed its commitment to the security and integrity of the Arbitrum community without impacting any Arbitrum users or applications.” The funds had been transferred to what Arbitrum described as an intermediary frozen wallet. On-chain intelligence firm Arkham confirmed the action via X: ”ARBITRUM RECOVERS $70.9M FROM KELPDAO EXPLOITER. The Arbitrum Security Council just removed $70.97M ETH from the KelpDAO Exploiter’s addresses. They sent it to the address 0x0000000000000000000000000000000000000DA0. North Korea stole the money and Arbitrum stole it back.” ARBITRUM RECOVERS $70.9M FROM KELPDAO EXPLOITER The Arbitrum Security Council just removed $70.97M ETH from the KelpDAO Exploiter’s addresses. They sent it to the address 0x0000000000000000000000000000000000000DA0 North Korea stole the money and Arbitrum stole it back. pic.twitter.com/4H2FbzyZss — Arkham (@arkham) April 21, 2026 The frozen ETH is just one part of a much larger incident, as NewsBTC reported. KelpDAO was exploited on April 18 for about $290 million. LayerZero describes the event as isolated to KelpDAO’s rsETH configuration and tied to a single-DVN setup rather than broader contagion across the protocol. In a separate statement, KelpDAO said the April 18 incident involved a forged cross-chain message and later thanked Arbitrum’s council, ecosystem stakeholders and SEAL 911 for helping coordinate the response. “We appreciate the recent decision by the Arbitrum Security Council to take action in response to the LayerZero-DVN/rsETH incident of April 18. Over the past two days, the KelpDAO team has worked closely and constructively with members of the security council […] We would like to particularly acknowledge the exceptional efforts of Security Alliance’s SEAL 911 among countless others, whose coordination, information structuring, and stakeholder engagement were instrumental in bringing clarity and urgency to this process,” KelpDAO via X. We appreciate the recent decision by the @arbitrum Security Council to take action in response to the LayerZero-DVN/rsETH incident of April 18. Over the past two days, the KelpDAO team has worked closely and constructively with members of the security council and broader… https://t.co/E7CHGbypPc — Kelp (@KelpDAO) April 21, 2026 Arbitrum Sparks Fresh Decentralization Debate That left the industry arguing over two different questions at once: whether the recovery was justified, and what it says about the systems involved. Griff Green, a member of Arbitrum’s Security Council, framed the decision as an extraordinary but necessary intervention. “We did not make this decision lightly, there were countless hours of debates, technical, practical, ethical and political,” he wrote. “But all it takes for evil to triumph is for good men to do nothing, so today, we decided to do something.” The comment carried extra weight because Arbitrum’s council is not an abstract mechanism; it is a 12-member committee elected by the DAO to handle critical risks and emergency decisions. Critics, though, saw the same event very differently. In one of the sharper reactions on X, commentator Deestar (@Deestar) argued that “while this is really great news, it’s a proof that almost nothing in crypto is truly decentralized.” so basically Arbitrum security council moved $71 million in ETH out of the hackers wallet desperate times shows the true nature of crypto space the security council that made this decision are just 12 people, likely in the same location while this is really great news it’s a… https://t.co/zkgFNCsU0o pic.twitter.com/zYizGovwwk — Deestar (@Deestar) April 21, 2026 He pushed the point further: “If your government comes after your money, only Bitcoin can save you.” That critique is more polemical than technical, but it goes straight to the fault line this episode exposed. A network can call itself decentralized, yet still retain a small, coordinated emergency body with the power to seize control of assets (when the stakes are high enough). At press time, Arbitrum (ARB) traded at $0.1266. Featured image created with DALL.E, chart from TradingView.com