- Kelp DAO and Aave are restarting rsETH operations after recovery efforts
- Over $300 million was raised through the DeFi United initiative
- Kelp upgraded security settings and is migrating away from LayerZero
- The exploit remains the largest DeFi hack of 2026
Recovery Efforts Continue After Massive Kelp Exploit
Kelp DAO and Aave announced plans to gradually restore rsETH-related operations following last month’s $292 million exploit tied to Kelp’s LayerZero bridge infrastructure.
The attack, widely attributed to North Korea’s Lazarus Group, became the largest decentralized finance exploit of 2026 and created severe bad debt exposure across several DeFi lending protocols.
As part of the recovery plan, Kelp stated that 117,132 rsETH tokens stolen during the exploit will be progressively restored over the next two weeks.
Withdrawals And Bridging Set To Resume
Kelp said withdrawals could resume within 24 hours after the first refill tranche reaches the LayerZero OFT adapter.
Once contracts are fully unpaused, users will again be able to deposit, redeem, bridge, and claim rsETH normally across supported networks.
The protocol also introduced several major security upgrades following the incident.
Security Measures Significantly Strengthened
Kelp confirmed that it increased the number of bridge verification attestors from one to four independent validators while also raising required block confirmations from 42 to 64.
The project additionally deprecated all Layer 2-to-Layer 2 routes and announced plans to fully migrate to Chainlink CCIP infrastructure instead of continuing to rely on LayerZero.
The migration reflects growing concerns throughout DeFi over cross-chain bridge security after multiple large exploits over the past two years.
DeFi United Raised Over $300 Million
The broader recovery effort has been coordinated through “DeFi United,” an industry-wide initiative led largely by Aave and supported by multiple DeFi protocols and investors.
The initiative reportedly raised over $300 million worth of ETH to stabilize the ecosystem and reduce systemic fallout from the attack.
At the same time, legal complications continue surrounding approximately $72 million worth of frozen ETH held on Arbitrum. Plaintiffs tied to terrorism-related lawsuits against North Korea attempted to claim the frozen funds, temporarily delaying the transfer process.
After emergency legal filings from Aave, courts ultimately allowed the ETH transfer to proceed, though restrictions on moving or selling the funds remain in place.
LayerZero Publicly Admits Mistakes
The incident also triggered a rare public admission from LayerZero.
Initially, LayerZero blamed Kelp DAO for using a risky single-verifier setup. Kelp later responded that the configuration had been recommended during onboarding.
LayerZero has since acknowledged that allowing 1-of-1 verifier configurations for large-value bridges created unacceptable security risks.
The episode is likely to influence future security standards for cross-chain infrastructure throughout the DeFi sector.