Just in:
OpenAI agents accessed three U.S. government websites // Salesforce patches Agentforce flaws enabling zero-click data theft // Angel Health Wan Chai Clinic Commences Operations, Providing General Practice, Health Check and Vaccination Services // Bitget chief links $387.5 million breach to North Korea // From Holiday Getaways to Meaningful Journeys: How Le Méridien Phuket Mai Khao Beach Resort Is Reshaping the Festive Season // RemControl enables remote takeover of Android banking devices // Long-lived Linux kernel flaw permits root container escape // MIHAS Reaffirms Malaysia’s Pivotal Role in the Growing Global Halal Economy // From City Apartments to Villa Communities: Exploring Binghatti’s Dubai Portfolio // Hawaii braces as Hurricane Nolo threatens catastrophic flooding // Trump targets $810 million in congressionally approved spending // Green SM starts Amsterdam electric taxi pilot // Bitcoin rally lifts Tesla holdings towards $1 billion // Kweichow Zhenjiu Partners with CDF Cruise to Host Exclusive Tasting Event Aboard “Adora Magic City” // Google, OpenAI and Anthropic advance AI standards plan // DP World maps shifts in maritime trade // Keralam Govt Stays Implementation Of Minimum Marks In Schools // UNGA 81 Day 3: Gaza, Iran War And The Limits Of Multilateral Diplomacy // Huagui Group: A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content // President Xi Dominates US-China Summit, But Trump Has His Winning Cards //

Bridge breach sends DeFi reeling

 

Hackers exploited a cross-chain bridge tied to liquid restaking protocol Kelp DAO on Saturday, draining about $290 million in rsETH and sending shockwaves through decentralised finance markets as the losses spread into lending platforms and renewed questions over the security of multichain infrastructure. Bloomberg reported the theft at nearly $300 million, while market and on-chain reports put the value at roughly $292 million to $294 million.

The exploit centred on Kelp DAO’s LayerZero-powered bridge for rsETH, a token used across multiple chains and DeFi applications. Coindesk reported that about 116,500 rsETH, equal to roughly 18% of circulating supply, was drained from the bridge. Other industry reports said Kelp DAO acknowledged unusual cross-chain activity and paused affected rsETH contracts on mainnet and layer-2 networks while it worked with security specialists.

What elevated the incident from a large theft to a broader DeFi shock was the way the stolen or unbacked assets were allegedly used across interconnected protocols. Several reports said the attacker moved rapidly to deploy the compromised rsETH as collateral and extract hard assets such as wrapped ether from lending venues including Aave, with spillover also discussed around Compound and Euler. Forbes reported that the fallout left Aave’s wETH pool facing roughly $177 million to $200 million in bad debt, turning a bridge exploit into a system-wide stress event.

That chain reaction has revived a long-running concern in crypto markets: composability can magnify losses just as efficiently as it amplifies growth. Academic work on bridge design has warned that cross-chain systems often carry weaker security guarantees than the base blockchains they connect. A 2024 study of bridge exploits found that bridging architectures contain multiple recurring design flaws and vulnerability types, while later survey work in 2026 again pointed to bridges among the largest historical sources of DeFi losses.

The early technical explanation emerging from security researchers suggests the breach may not have stemmed from a failure of Kelp DAO’s core restaking contracts, but from the bridge configuration that governed cross-chain message validation. One detailed analysis said a forged cross-chain message was accepted because the bridge relied on a one-of-one validator or verifier setup, allowing the attacker to induce the escrow contract to release tokens that should not have moved. That distinction matters for markets because it means the weakness may have sat in the interoperability layer rather than in the underlying asset pool itself, though users and lenders still bore the market impact.

The event also underscores how quickly risk migrates once a token is widely used as collateral. When a bridged asset loses credibility or backing, lending markets that still price it optimistically can become transmission channels for losses. Similar contagion dynamics were seen in other DeFi incidents this year, where a hacked or depegged asset retained collateral value long enough for attackers to borrow against it, leaving protocols and depositors to absorb the damage.

For the broader digital-asset industry, the timing is awkward. Chainalysis said stolen funds remained a major threat to the ecosystem in 2025, with North Korea-linked hackers alone stealing $2 billion, while Elliptic said more than $21.8 billion in illicit and high-risk crypto had been laundered using cross-chain methods. Those figures do not describe this case directly, but they show how bridges and multichain routes have become central both to theft and to the movement of stolen funds after an exploit.

Saturday’s breach appears set to rank among the biggest crypto hacks of 2026. Before this, major incidents this year had included the attack on Drift Protocol and earlier losses at Step Finance, but the Kelp DAO exploit has overtaken most of them in scale and in the breadth of knock-on effects. That has sharpened scrutiny of bridge operators, auditors and protocols that accept bridged assets as collateral without stronger circuit breakers, oracle controls or emergency pricing mechanisms.

 

Arabian Post – Crypto News Network

 



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Trump targets $810 million in congressionally approved spending // Iran proposes uranium transfer in US diplomacy push // Data displaces skills as threat hunting barrier // Huagui Group: A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content // RemControl enables remote takeover of Android banking devices // From City Apartments to Villa Communities: Exploring Binghatti’s Dubai Portfolio // Discord deploys machine learning to classify user ages // Keralam Govt Stays Implementation Of Minimum Marks In Schools // Binance opens bStocks access to UAE users // MIHAS Awards 2026 Celebrates Excellence and Sets New Benchmark for Innovation, Sustainability and Digitalisation Across the Global Halal Ecosystem // From Holiday Getaways to Meaningful Journeys: How Le Méridien Phuket Mai Khao Beach Resort Is Reshaping the Festive Season // Long-lived Linux kernel flaw permits root container escape // Hawaii braces as Hurricane Nolo threatens catastrophic flooding // Green SM starts Amsterdam electric taxi pilot // Bitget chief links $387.5 million breach to North Korea // Bitcoin rally lifts Tesla holdings towards $1 billion // UNGA 81 Day 3: Gaza, Iran War And The Limits Of Multilateral Diplomacy // Amari Koh Samui and OZO Chaweng Samui invite active travellers to fill their trip with more of the experiences they love // Kweichow Zhenjiu Partners with CDF Cruise to Host Exclusive Tasting Event Aboard “Adora Magic City” // Angel Health Wan Chai Clinic Commences Operations, Providing General Practice, Health Check and Vaccination Services //