The Kelp Exploit: Assessing Positioning and the Potential Consequences for DeFi
The Kelp Exploit: Assessing Positioning and the Potential Consequences for DeFi
On April 18, 2026, liquid restaking protocol Kelp experienced an exploit. An attacker was able to mint 116,500 rsETH ($290M) without backing via its LayerZero route and proceeded to borrow around $190M of ETH and related assets on the lending protocol Aave, across Ethereum and Arbitrum. This raises concerns about the possibility of bad debt accumulation, the full extent of which remains uncertain and subject to ongoing assessment. Approximately 30,000 ETH was recovered by Arbitrum after its Security Council took emergency action.
With immediate ETH recovery attempts likely complete, attention now shifts to the recovery. We explore what market positioning tells us here and examine the second order effects for the DeFi space.
Selected Market Data and Our Interpretations
AAVE fell nearly 25% in the 48 hours following the exploit as the market digested the impact on the protocol. From the lows, AAVE climbed 9%. The partial price recovery could be interpreted by some market participants as reflecting reduced concern about bad debt outcomes. Interestingly, funding did not turn strongly negative until well after the event, suggesting the initial move down was spot driven. As of the observation date, funding rates had not reflected strong net short positioning among perpetual futures traders. While funding has since normalized, AAVE’s perp futures open interest remains 45% above levels prior to the exploit, per data from Velo, suggesting positioning has not reset yet. This interpretation is speculative and price movements alone are not a reliable indicator of protocol solvency or future performance.
ZRO saw similar price action, declining 20% initially before recovering 7% from the lows. However, with its funding closer to 0%, perps traders are demonstrating more of a negative bias, which could indicate concerns over the role of its technology in the exploit. ZRO perps futures open interest is roughly flat to before the event, per data from Velo, suggesting immediate positioning has reset.
ETH performance suggests investors may be looking past the exploit. Although TVL fell 40% in the days after the event, per data from Artemis, ETH price ($2400) on April 22 was higher than at the time of the exploit ($2350). Per Coin Metrics data as of April 22, 2026, ETH perpetual futures funding rates had turned positive. This could be a signal that the value of an L1 should reflect more than the success of its DeFi ecosystem and mirrors SOL’s full recovery after the Drift exploit earlier in the month, although the full impact of both exploits are still unknown.
Weaknesses Exposed
Bridged assets are not the same as native assets. The rsETH situation exposes risks that multi-chain tokens could be minted unbacked. The exploit illustrates that some DeFi protocols may have limited verification mechanisms for whether deposited assets are fully backed, as evidenced by the rsETH situation described above. The extent to which this applies across the broader DeFi ecosystem varies by protocol.
Circuit breakers must be implemented. The fact that the attacker rapidly deposited unbacked rsETH and was able to take out $100M+ of loans without thorough checks highlights areas of improvements in the future. Protocols could seek to implement a multi-hour waiting period for large deposits to be usable and/or for large loans being taken out, giving security researchers time to monitor and respond.
Collateral and LTVs should be reevaluated. To fuel growth, many DeFi protocols accepted collateral that could have points of weakness, such as depegs or bridge vulnerabilities. To solve this, protocols may look to restrict acceptable collateral to only native, non-derivative assets. However, this could result in a smaller addressable market and limit revenue potential for lending protocols.
Second Order Effects
Interest rates in DeFi may rerate to better reflect risks. For the past few months, stablecoin yields across lending protocols compressed to levels below that of U.S. treasuries.
Shift to L1. Arbitrum’s move to confiscate the attacker’s ETH highlights potential concerns around decentralization of L2s, with leading L2s still at Stage 1 decentralization, per L2 Beat. This means their respective Security Councils can take action unilaterally.
Insurance funds may need rethinking. Aave’s Umbrella staking module has around $250M of assets, but these are intended to be used for backing the specific markets. For the WETH market on mainnet, the roughly ~$50M of WETH in Umbrella pales in comparison to the estimated ~$90M of ETH bad debt, as calculated by Llama Risk.
TVL could take time to recover given AI overhang. Greater AI capabilities (Mythos) and 2 large hacks in a row (Drift and Kelp) are heightening concerns over DeFi security.
Pooled vs isolated exposure. The exploit highlights the potential for shared liability in a pooled lending architecture where depositors of any eligible borrowable assets could be impacted by issues with a given collateral asset. This environment highlights the utility of isolated risk models.
Centralized or whitelisted lending may look more attractive. The episode could support the potentially more diligent risk management of CeFi lending, or the safeguards that whitelisted DeFi instances support.
The industry now has an opportunity to implement best security practices and risk management to help prevent such scenarios in the future.