KelpDAO
Incident posture
Timeline
Summary
KelpDAO experienced a exploit that drained roughly $291 million after attackers compromised a validator responsible for cross-chain message verification, revealing a failure in operational security rather than a smart contract flaw. The breach was carried out through an extended social engineering campaign that gave threat actors control over key management and multisig governance, enabling them to move funds on chain; this method mirrored a concurrent attack on another DeFi platform and together the two events represented a large portion of the losses recorded in the period, with investigators attributing the activity to North Korean‑linked groups.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 18 2026 the decentralized finance platform KelpDAO experienced a security breach that resulted in the loss of approximately $291.3 million in cryptocurrency. The attack was attributed to the North Korean advanced persistent threat group known as TraderTraitor, also tracked as Jade Sleet (UNC4899). Analysis indicated that the breach originated from a single compromised validator responsible for cross‑chain message verification, which the attacker used to divert funds. The platform’s smart contracts were examined and found to contain no vulnerabilities, meaning the exploit did not involve a code bug.
The KelpDAO loss contributed to a total of $1.315 billion stolen across 344 on‑chain incidents in the first half of 2026. Together with the concurrent Drift Protocol breach, the two incidents accounted for nearly 44 % of the period’s losses, highlighting a shift toward attacks on operational infrastructure rather than contract code. In the month of April alone, crypto hacks reached a record $651 million across 29 incidents, with KelpDAO and Drift combining for roughly $579 million of that total. The incident was also cited in reports showing that North Korean actors were responsible for 76 % of all cryptocurrency stolen in 2026, with the Drift and KelpDAO exploits representing the bulk of those gains.
Technical descriptions of the KelpDAO attack emphasized that the attackers exploited a single point of trust in the validator infrastructure, noting a lack of provenance validation for assets moving between systems and governance structures that could not respond at the speed of the operation. Analysts observed that the incident illustrated how decentralized finance protocols, which often handle nation‑state‑scale value with startup‑level security, are vulnerable to sophisticated actors who understand these weak points. The attack chain was described as distinct from the months‑long social engineering operation that preceded the Drift breach, yet both demonstrated the attackers’ extensive technical understanding of the targeted platforms.
In the aftermath, security observers and experts highlighted the need for stronger operational security practices, distributed key‑management controls, and automated real‑time trust validation at the transaction layer. They noted that reliance on governance votes and multisig approvals that require hours or days would not withstand attacks executed by AI‑empowered adversaries operating in minutes. The incident was repeatedly referenced in discussions about the importance of improving key management and multisig governance to mitigate wallet‑compromise risks, which had become the costliest attack vector in the reporting period.
Sources
Sources available to members: 3 sources.