Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Kelp DAO Exploit Aftermath: Hacker Launders $220 Million in Record Time, Recovery Hopes Nearly Vanish

Only a small fraction of the stolen funds remains traceable after the attacker rapidly moved assets through THORChain, Tornado Cash, and Bitcoin privacy tools following the $292 million Kelp DAO exploit.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 2, 2026
in Security & Hacks
0 0
Kelp DAO Exploit

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

The attacker behind the massive Kelp DAO bridge exploit has successfully laundered roughly $220 million of the stolen funds in just 45 days, effectively destroying any realistic hopes of recovering the unfrozen portion of the haul.

On-chain intelligence firms now report that roughly $220 million of the approximately $292 million stolen in the April 18 incident has been moved through advanced cross-chain privacy tools. Only around $1.7 million remains visibly linked to the original exploiter wallets, effectively closing the window for meaningful asset tracing on that slice of the haul.

The operation stands out not just for its scale but for the speed and sophistication with which the funds were dispersed. Security researchers continue to attribute the attack with high confidence to TraderTraitor, a subgroup under North Korea’s Lazarus ecosystem, the same actors linked to several other high-value exploits this year.

Anatomy of the Laundering Trail

Following the initial exploit, which targeted a weakened 1-of-1 verifier setup on Kelp DAO’s LayerZero-powered bridge, the attacker wasted little time. After Arbitrum’s Security Council took the unusual step of freezing $71 million worth of ETH shortly after the hack, the remaining funds were funneled aggressively into privacy infrastructure.

Analysts tracked large transfers, including a notable $175 million move across three fresh Ethereum wallets, followed by heavy usage of:

  • THORChain for swapping into Bitcoin
  • Wasabi CoinJoin for Bitcoin-level privacy
  • Tornado Cash for Ethereum mixing cycles
  • Umbra and other obfuscation protocols

This multi-layered approach caused temporary spikes in volume on these platforms and highlights how state-linked actors are increasingly comfortable operating across chains to evade detection.

The $71 million still frozen on Arbitrum remains the only significant recoverable amount, though even that faces complications from ongoing legal claims, including forfeiture actions tied to prior judgments against North Korean entities.

Protocol Recovery vs On-Chain Reality

While the laundering arc appears largely complete for the unfrozen funds, Kelp DAO and its partners moved quickly on the protocol side. Through a coordinated effort dubbed “DeFi United,” involving Aave, EigenLayer, Karak, and others, the team restored the majority of user rsETH positions. The protocol also migrated its bridging to Chainlink’s CCIP for stronger security.

LayerZero, for its part, released a detailed incident report in May, in collaboration with Mandiant and others, confirming the configuration downgrade that enabled the attack and announcing that it would no longer support single-verifier setups.

Yet these measures, while protecting users from further immediate losses, do little to claw back the laundered capital now scattered in the shadows of the blockchain.

What This Means for DeFi

The Kelp DAO case adds to a troubling pattern in 2026: sophisticated actors exploiting bridge weaknesses and rapidly converting gains into untraceable forms. With North Korean groups reportedly responsible for a large share of this year’s exploit volume, the industry faces renewed pressure to balance innovation with robust security architecture.

For builders, the message is clear: bridge configurations, oracle dependencies, and emergency response mechanisms need constant scrutiny. For users and investors, it serves as a reminder that while DeFi offers unprecedented opportunities, certain risks, especially around cross-chain infrastructure, remain stubbornly high.

As forensic teams and law enforcement shift focus toward broader sanctions-style interventions rather than wallet-by-wallet recovery, the Kelp incident may ultimately be remembered not just as a massive hack, but as a case study in how quickly nine-figure thefts can disappear in today’s privacy-enhanced crypto environment.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: Crypto Hacks
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days
Security & Hacks

More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days

by Saravana Kumar Mahendran
August 31, 2026

More Markets, a lending protocol built on Flow EVM, lost about $9.3 million on Sunday after an attacker used a...

Read moreDetails
Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

August 29, 2026
Avici Confirms $500,859 Refund to 1,685 Users After Rain Contract Flaw

Avici Confirms $500,859 Refund to 1,685 Users After Rain Contract Flaw

August 29, 2026
Sandbox’s $1 trillion in phantom SAND is still frozen. The real bridge hack cost under $700,000.

Sandbox’s $1 Trillion Phantom SAND Frozen as Real Hack Cost Hits $700K

August 28, 2026
Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

August 27, 2026
Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

August 25, 2026
Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

August 25, 2026
Next Post
Solo Bitcoin Miner Wins Block 951771

Solo Bitcoin Miner Wins Block 951771, Earns Around $232,000 Reward With Home Mining Setup

EDGE Token Drops 70% as edgeX Investigates Abnormal Price Crash and Market Manipulation Claims

EDGE Token Drops 70% as edgeX Investigates Abnormal Price Crash and Market Manipulation Claims

Recommended

  • All
  • Crypto News Today
Bitcoin Spot ETFs Pull In $924M Last Week as BlackRock’s IBIT Leads

Bitcoin Spot ETFs Record $924.48M, Ethereum ETFs Add $824.42M in Net Inflows

August 31, 2026

Metaplanet Transfers 3,200 BTC Worth $248.67M to Coinbase Prime

August 31, 2026
Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

August 31, 2026
Trump-Linked GOLD Token Crashes 99% Days After Eric Trump Denied Any New Coin

Trump-Linked GOLD Token Crashes 99% Days After Eric Trump Denied Any New Coin

August 29, 2026
Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

August 29, 2026
Bitcoin ETFs Reverse Course With $202M Outflow After Nine-Day Run

Bitcoin ETFs See $202M Outflow, Ending 9-Day Inflow Streak

August 29, 2026
Cardone Capital's 1,200 BTC Buy Blows Past Its Own 2026 Bitcoin Target

Cardone Capital’s 1,200 BTC Buy Blows Past Its Own 2026 Bitcoin Target

August 29, 2026
Kalshi Loses Nevada Appeal, Deepening U.S. Prediction Market Legal Split

Kalshi Loses Nevada Appeal, Deepening U.S. Prediction Market Legal Split

August 29, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days
  • Bitcoin Spot ETFs Record $924.48M, Ethereum ETFs Add $824.42M in Net Inflows
  • Metaplanet Transfers 3,200 BTC Worth $248.67M to Coinbase Prime

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.