Skip to main content
zeroShadow

Hacks

Threat Intelligence

KelpDAO: Dealing with the biggest hack so far in 2026

Aug 25, 2026 | 7 min read

In April 2026, the rsETH LayerZero bridging adapter for KelpDAO was compromised via an off-chain RPC node poisoning attack, resulting in a $292 million theft. zeroShadow was retained to manage the live incident response, deploying a 24/7 team to follow the funds cross-chain and test live freezing efforts.

A visual of fire spreading representing the path of illicit funds

In April 2026, the rsETH LayerZero bridging adapter for KelpDAO was compromised via an off-chain RPC node poisoning attack, resulting in a $292 million theft.

The launderers moved the stolen assets across the Bitcoin, EVM, and TRON networks. The initial Bitcoin to EVM layer relied entirely on decentralized bridges where defenders can only introduce friction to slow down attackers, not freeze assets completely. Over 20 services quickly onboarded to TIPzs to create this friction. While this slowed the attack down, a large portion of the assets passed through before the teams requested TIPzs access.

summary of flow of funds from EVM to Bitcoin mixers to Tron

The best opportunity to freeze assets was at the EVM to TRON layer. However, the Bitget Wallet Bridge lacked the threat data needed to make an informed decision in time. We supplied data manually to help their compliance staff update internal blocklists, but manual communication could not keep pace with the 24/7 velocity of DPRK laundering. Consequently, the remaining volume moved without delay or friction.

The actual transaction data shows a clear difference between platforms that stopped the attackers and those that let the funds pass through. The following sections break down the exact obfuscation methods the launderers used, how they adapted to TIPzs updates, and the specific compliance vulnerabilities identified during this incident.

The trace: dissecting the cross-chain pipeline

The initial phases of the KelpDAO laundering operation mirrored the 2025 Bybit methodology, but introduced specific routing modifications designed to increase transaction speed:

Creating friction: accurate threat intel at speed

To try and create friction and stop the laundering we approached all services receiving KelpDAO assets with an offer to onboard TIPzs and get our free threat data in real time. This added 20 new members to Hermod production environments, with another 100+ in trial. Local container setups are completed in a matter of hours, and our live engineering team directly manages the integration to ensure any localized environment issues are resolved immediately.

Once these endpoints were live, zeroShadow incident responders used our direct write access to feed newly identified CoinJoin withdrawal signatures onto the live threat rails in under 10 seconds. This real-time sync forced an immediate sequence of operational adjustments as the launderers adapted:

Temporary threat indicators

Grouping these mixer addresses together was a temporary step to stop the launderers. Flagging the entire mixer round created too many obstacles, forcing the launderers to give up on that bridge route. As soon as we saw the launderers stop using those mixer blocks, we took the flags off so innocent users could use the bridges again.

Blocklists need to be flexible. Risk in crypto changes constantly, meaning certain platforms become higher-risk during specific events. When the DPRK steals over $100 million and immediately tries to use Wasabi Wallet, platforms must adjust their screening to block that threat. Once that risk drops, lifting those restrictions should be just as straightforward.

Testing bridge defenses

Looking at how security tools affect a bridge's daily operations gives us useful data. No security system can stop all stolen funds, and it is unrealistic to claim you can block every single hack. Instead, the real goal is to make things as difficult as possible for DPRK launderers. Adding our Hermod agent helped protocols detect illicit downstream laundering in real time. The data on these blocked transfers shows exactly how a protocol setup changes the way hackers behave.

chart of different blocks against illict funds

The above chart shows a small sample of our members who were running Hermod during the later KelpDAO laundering period. Some of our members recorded a higher number of blocks than others, and we wanted to understand why this was.

When we took a closer look, it became apparent that systems that had a built-in revert delay for rejected transactions had fewer retry attempts. When funds were returned instantly, we noticed that the launderer would move to a new address and try again several times. But when a time penalty was imposed, they made fewer retry attempts.

Introducing this delayed revert friction sometimes deterred DPRK launderers from interacting with certain protocols. This can be a difficult proposition, as protocols are typically (and rightly) optimized for legitimate users. The question protocols should consider is, “can I introduce friction if I get a threat detection on my screening agent?”, because our data reveals that this friction can sometimes deter DPRK laundering.

Manual processing and centralized liquidity loops

movement of funds to Bitget

Once funds cleared the EVM bridge layers, they hit the Bitget Wallet Bridge. Processing up to $10 million per day during peak activity, this route carried approximately 80% of the total observed laundering volume, as the launderers sought to move assets from EVM to the TRON network.

This volume exposed the limits of manual compliance workflows. During the incident, security groups shared threat indicators via Telegram channels, requiring compliance staff to manually input bad addresses into blocklists. The pace of the attack made this approach ineffective. The threat actor generated new wallets faster than human teams could coordinate, moving assets before updates were executed.

The sheer volume of transactions eventually depleted the bridge's available TRON liquidity. To prevent the bridge from halting operations, the pool was replenished by recycling the incoming illicit assets. Our on-chain forensic tracking showed that the USDC and USDT received by the Bitget Wallet Bridge Ethereum address from DPRK-linked swaps were swept directly into a Bitget Exchange deposit address . The equivalent value was then withdrawn as clean USDT on the TRON network, routing it directly back to the bridge liquidity pool .

As the retained incident response team, we preserved this transaction data and shared it directly with law enforcement task forces and downstream services like Bitget. This cross-chain evidence documented the exact route used to sustain the pipeline, providing investigators with the verifiable data needed to isolate off-ramps and coordinate targeted enforcement actions.

Conclusion and acknowledgements

To protect privacy, we do not name our clients and have hidden most of the services in this report. We named the Bitget Wallet Bridge because it was the primary route for EVM-to-TRON transfers, handling the vast majority of the laundering volume. Because the blockchain is public, anyone can see these massive transaction spikes, so trying to hide the name would not work.

We thank our TIPzs members for letting us share these details. This case is a learning opportunity for the whole industry, showing how different setups can add friction and lower exposure to high-risk assets.

We approached every service exposed to DPRK laundering risk during this incident. We offered them quick onboarding for free screening. This is not a temporary trial. Our Core subscription is permanently free and covers all major hacks we investigate, including this one and future TraderTraitor attacks.

Our offer still stands for any service that wants better risk screening for the biggest hacks in Web3.

Share this post