x
Black Bar Banner 1
x

Alert!  New Secured Wallets are installed! new Blog system with AI  power and auto blog curation coming soon  Alert! 

Ads by Markethive - View All
Blogs
The Blog Feed
Write a New Blog Post
Search Blog Status
Most Viewed
Most Recent
Most Shared
Alphabetical
Blog Main Menu
Markethive Blog (default)
All Blogs
My Blog Posts
Friends' Blogs
Blog Categories
All
Advertising
Blockchain & Cryptocurrency
Business Development
Diet & Weight Loss
Environmental
Health and Wellness
History and Culture
Home and Garden
Marketing
Mentoring & Training
Money & Finance
Other
Political
Prayer & Religion
Programming & Technical
Real Estate
Search Engine Optimization
Social Media
Spirituality
Sports & Recreation
Transport
Travel & Events
Website Design
Blogging Tools & Assets
My Blog Info
Members Subscribed to You
Blogs You Are Subscribed To
Website Widget
Wordpress Plugin
Subscribe for Greater Services
Subscribe to one of many subscriptions, each one includes the previous ones.. Unlock powerful tools, advance features, to build a powerful reach.

Massive crypto hack triggers $9 billion panic withdrawal

Posted by Bill Rippel on April 21, 2026 - 3:35am


Massive crypto hack triggers $9 billion panic withdrawal

A nearly $300 million exploit on a smaller crypto project has sent shockwaves through the decentralized finance (DeFi) industry.

Panic over the weekend caused investors to pull $9 billion from Aave, the market's largest lending platform, creating a massive liquidity crisis.

The chaos started when hackers took about $200 million of stolen digital tokens and deposited them onto Aave. Instead of selling the stolen funds immediately, the attackers used them as collateral to borrow other cryptocurrencies.

This unusual move terrified everyday depositors, who feared the collateral backing the platform might now be worthless.

According to data from industry tracker DefiLlama, the net outflows since the news broke on Saturday have slashed Aave’s total value locked by more than a third, dropping it down to $17.5 billion.

At press time, the native Aave token was trading at $90.42, reflecting a 2.54% decline over the past 24 hours.

Related: Major DeFi hack becomes the largest of 2026 yet

The Kelp DAO bridge exploit

The stolen funds originated from Kelp DAO, a liquid restaking protocol. Users deposit popular assets like Ether into Kelp and receive a "receipt" token called rsETH in return.

To allow rsETH to operate across more than 20 different blockchain networks—including Arbitrum, Base, Linea, and Scroll—Kelp utilizes a cross-chain bridge.

On Sunday at 17:35 UTC, the attacker targeted LayerZero, the software system that allows these blockchains to communicate. The attacker successfully tricked LayerZero’s EndpointV2 contract into believing a legitimate instruction had arrived from another network.

As a result, the Kelp bridge released 116,500 rsETH directly to the attacker. This haul represented roughly 18% of the entire 630,000 circulating supply of rsETH.

Kelp DAO’s emergency team responded 46 minutes later at 18:21 UTC by activating a protocol-wide pause, freezing all deposits, withdrawals, and the rsETH token itself.

Trending on TheStreet Roundtable:

Unusual tactics and North Korean links

Usually, hackers use tools like crypto mixers to hide and launder their stolen funds. In this case, the attacker funded a wallet using the privacy tool Tornado Cash about 10 hours before the strike.

However, rather than simply cashing out, they borrowed an estimated $236 million across multiple platforms using the stolen rsETH, with the bulk of the activity happening on Aave, according to cybersecurity firm PeckShield.

To stop the bleeding, Aave responded by freezing rsETH markets. On Sunday, the platform stated in an X post that its analysis shows the rsETH traded on the Ethereum blockchain remains fully backed, but restrictions will stay in place as a precaution.

Despite the reassurance, many users chose to withdraw their funds because it was unclear who would cover any potential losses if the tokens were effectively minted out of thin air.

Cybersecurity researcher Cyvers and LayerZero both indicated that the hackers are likely affiliated with North Korea, given the massive scale and sophistication of the attack.

This breach highlights the persistent vulnerabilities of cross-chain bridges and comes just weeks after $280 million was stolen from Drift Protocol, another DeFi platform.

Simon Keighley A powerful illustration of how quickly trust can unravel in DeFi, reinforcing the need for stronger safeguards and transparency across interconnected protocols.
April 21, 2026 at 5:01am