Kelp DAO (rsETH)
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED AFTER A REALIZED CONTROL FAILURE. On 2026-04-18, a forged cross-chain packet released 116,500 rsETH, worth about $292M at the time, from Kelp’s Ethereum LayerZero adapter without a corresponding source-side burn. The old memo’s “$196M of Aave bad debt” was not a settled figure: Aave service providers initially modeled multiple loss-allocation scenarios, and the recovery changed them. LayerZero’s final report says the application owner had changed a prior 2-of-2 verification setup to a single 1-of-1 DVN; compromise of LayerZero internal RPC infrastructure plus denial of service against a third-party RPC was then sufficient. Mainnet restaking contracts and EigenLayer deposits were not exploited, but the bridge was part of the rsETH product and its weakest configuration governed holder solvency. An ecosystem recovery ultimately restored backing, while Kelp retired bridging on 19 networks and left stranded holders a manual, quarterly recovery path. Recovery is positive conduct, not evidence the original control was acceptable. The v1 rejection remains.
- Any contract, oracle, interface, bridge or backing impairment during the 24-month reopening observation period
- Any supported bridge using a single verifier, single provider, or configuration change without an enforced exit delay
- Any issued rsETH not continuously covered by independently verifiable backing
- Any unapproved LST, EigenLayer operator, AVS, oracle, or cross-chain deployment entering the risk set
- Proposed-size mainnet withdrawal or market exit exceeding the written timing or slippage limit
The research file
The mechanism and risk stack
On Ethereum, Kelp accepts ETH and supported liquid-staking tokens, deploys them through EigenLayer and issues rsETH as a liquid claim on the pooled restaked assets and accrued rewards. An oracle and configuration layer determine the rsETH exchange rate and accepted assets; withdrawals use dedicated queue/converter contracts. That base claim adds Ethereum validator, LST issuer, EigenLayer, AVS operator, oracle, upgrade and withdrawal-timing risks. Cross-chain rsETH adds a second solvency system: remote tokens rely on rsETH locked in an Ethereum adapter and authenticated burn/release messages. The April event proved that the remote verification configuration can dominate all other underwriting.
Who controls it
Kelp’s litepaper describes a risk committee recommending collateral, rewards, services and operators, with DAO votes intended to approve changes. The deployed system also uses a central LRT configuration and privileged operational roles; Sigma Prime flagged the need to keep configuration consistent across the token, deposit pool, oracle and node delegators. Most importantly, the application owner selected the bridge security stack and changed it from 2-of-2 to a sole LayerZero DVN. That operational choice made one attestation sufficient. The relevant control map must therefore include contract admins, committee/DAO process, oracle updater, EigenLayer operators, every supported LST and AVS, bridge owner, DVNs and RPCs.
Failure and recovery record
Kelp had already disclosed a July 2024 dApp UI attack; its post-mortem belongs in the operating record even though it was not a core-contract loss. On 2026-04-18, the bridge accepted a forged message and released 116,500 rsETH. Kelp initially stated that Ethereum backing and core restaking contracts remained intact. Aave service providers modeled $123.7M to $230.1M of potential bad debt before the Arbitrum Security Council froze 30,766 ETH; the updated modeled range became $62.4M to $162.5M depending on how losses were allocated. These were scenarios, not the old memo’s definitive $196M.
The coordinated recovery refilled the adapter and restored operations. LayerZero attributed the attack to compromised RPC infrastructure, a denial-of-service component and the owner-selected 1-of-1 DVN, with forensic firms attributing the attacker to DPRK-linked activity. Full restoration prevented the modeled loss from being the final holder outcome, but external rescue and governance intervention were necessary.
Exit and liquidity
A mainnet holder depends on Kelp’s withdrawal queue and the availability and unwind time of underlying ETH/LST positions; a market sale instead depends on rsETH depth and discount. Remote holders additionally depend on bridge backing and message security. After Kelp retired 19 networks on 2026-06-15, holders who missed the deadline must unwrap, permanently burn, pay a flat 100 USDC fee on Ethereum, email proofs to Kelp and wait for a quarterly settlement; that recovery window ends 2027-06-15. This is operationally incompatible with an institutional liquidity promise. No client position should rely on a chain whose ordinary bridge can later become a manual claims process.
Comparison and decision
Compared with native ETH staking, rsETH adds LST aggregation, EigenLayer/AVS and Kelp governance risks in exchange for liquidity and restaking rewards. Compared with a single-issuer LST, it diversifies inputs but makes look-through slashing, operator and oracle exposure harder to enumerate. Compared with other LRTs, the April failure is unusually decision-useful: audited Ethereum contracts did not protect a token whose cross-chain owner chose a one-verifier configuration. Chainlink Proof of Reserve can constrain minting or improve visibility, but it cannot authenticate a forged bridge message by itself. Recommendation: remain rejected across all chains; do not treat mainnet as automatically approved merely because its collateral survived this incident.
Observable reopening conditions
Require a final Kelp post-mortem reconciling every holder and protocol loss; a public authority map; independent audits of the live mainnet, withdrawal, oracle and cross-chain deployments; continuous proof of reserves covering every issued unit; and at least 24 months without a contract, oracle, UI or bridge loss after the recovery. Any bridge considered must use multiple organizationally independent verifiers with a threshold that survives loss of one provider, on-chain enforced configuration delay and monitoring, and an audited escape path. Proposed-size mainnet withdrawal and market sale must pass written timing and slippage limits. A points program, restored peg or higher APY cannot reopen the file.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Kelp — incident response, 2026-04-19 · primary · accessed 2026-08-14
Supports: 116,500 rsETH release, bridge scope, mainnet backing, core-contract status - LayerZero — final external Kelp incident report · primary · accessed 2026-08-14
Supports: $292M incident value, 1-of-1 DVN, RPC compromise, DPRK attribution, root cause - Aave service providers — rsETH incident report · primary · accessed 2026-08-14
Supports: forged packet, Aave exposure scenarios, adapter backing, market containment - Aave service providers — post-freeze loss-scenario update · primary · accessed 2026-08-14
Supports: 30,766 ETH freeze, $62.4M scenario, $162.5M scenario, recovery impact - Aave governance — rsETH incident funding and recovery plan · primary · accessed 2026-08-14
Supports: 40,373 rsETH recovery, ecosystem recapitalization, backing restoration plan - Kelp — sunset-network recovery process · primary · accessed 2026-08-14
Supports: 19 retired networks, 100 USDC fee, quarterly settlement, 2027-06-15 deadline - Kelp — rsETH litepaper · primary · accessed 2026-08-14
Supports: restaking mechanism, risk committee, DAO control, operator and AVS selection - Sigma Prime — Kelp liquid-restaking-token review · primary · accessed 2026-08-14
Supports: contract scope, LRT configuration, oracle and node delegator controls - Kelp — July 2024 dApp UI attack post-mortem · primary · accessed 2026-08-14
Supports: UI incident, operating record, response controls
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |