BlockThreat - Week 16, 2026
KelpDAO suffers the biggest hack of the year, Hyperbridge gets caught by its own joke. 17 incidents, $329M in losses, and many harsh lessons for bridges, node operators, and DeFi teams still relying on broken trust models.
Never a dull day in crypto. Just two weeks after AppleJeus hit Drift Protocol, another elite North Korean crew, TraderTraitor, pulled off an even bigger and more sophisticated operation against KelpDAO through LayerZero. Hyperbridge made an April 1 joke about getting hacked only to get hacked for real two weeks later. All told, the week ended with 17 incidents and $329,124,550 in losses. In this edition, we break down the KelpDAO and LayerZero disaster, multiple CeFi exchange incidents and threat actors behind them, and the other major compromises that made this one of the most painful weeks of the year.
Paid subscribers can read on for the full breakdown of the KelpDAO and LayerZero hack, incident response lessons, infrastructure failures, and the complete roundup of this week’s hacks, phishing and malware campaigns, research, tools, and other essential threat intelligence.
KelpDAO / LayerZero Incident
Let’s start with the biggest hack of the year and one of the clearest reminders to review your protocol's trust assumptions. On April 18, DPRK's TraderTraitor threat actor drained $292 million from KelpDAO by forging LayerZero messages for rsETH, stealing 116,500 rsETH in the process. LayerZero’s preliminary account points to a highly sophisticated operation that poisoned RPC infrastructure relied on by the DVN and exploited KelpDAO’s single DVN setup to push through fake attestations.
As is usual with incidents of this size, the damage did not stop at the bridge. The stolen rsETH was quickly pushed into Aave and used to borrow ETH before the market could fully contain the damage. Depending on how losses are socialized, Aave’s bad debt exposure is being modeled in a range of roughly $124 million to $230 million. In other words, one weak trust path on one bridge was enough to spill directly into the balance sheet of a $16B lending protocol. And then came the second order damage. Once the market understood the scope of the exploit, liquidity fled often at a loss. Whales rushed to unwind risk, DeFi protocols scrambled through emergency responses.
The finger pointing started almost immediately. KelpDAO says the story is bigger than a bad app level setting. LayerZero says the hack was made possible by KelpDAO’s 1 of 1 DVN configuration. Both things can be true. Just like with the Bybit/Safe hack, TraderTraitor found a way to compromise critical infrastructure and then picked the juiciest target. The problem was not just one bad setting, but a combination KelpDAO's misplaced trust into LayerZero's infrastructure which happily printed hundreds of millions without any circuit breakers or reviews until it was too late.
That is also why this incident should make the rest of DeFi uncomfortable. According Dune's recently published dataset, 589 projects have at least one path where `min_required_dvns = 1. That's roughly half of all projects! KelpDAO was the name on the headline, but any one of those projects could have been targeted as well causing a massive meltdown.
There are at least two bright spots. First, KelpDAO was able to respond fairly fast (about 1 hour) to halt the second exploit transaction that would have drained another $100M.
Second, after the attackers moved funds onto Arbitrum and left them there for the weekend, the Arbitrum Security Council took emergency action and clawed back 30,766 ETH, about $71 million tied to the exploit. Decisive intervention like that remains rare in this industry. It should not be controversial to say that this was the right move. This is to the stark contrast to Circle's actions in the recent Drift compromise which simply refuses to freeze well known attacker funds and is now getting sued for it. As one one member of the Arbitrum Security Council put it:
This stands in stark contrast to Circle’s response during the Drift compromise, where the company refused to freeze well known attacker funds and is now being sued over it. As one member of the Arbitrum Security Council put it:

While we wait for comprehensive post-mortems, there are already a few high level lessons that similar projects should adopt.
- Threat model your trust assumptions, identify weak points, and build mitigations around them. This should be standard practice, yet too many teams still stop at the audit checkbox and walk away with a false sense of security.
- Chains, bridges, and major DeFi operators should have incident response plans and playbooks ready to freeze attacker funds quickly when needed. Save the cypherpunk ideals for a world where the money flowing through your protocol cannot be used to fund ICBMs.
On the technical side, bridge operators review your DVN configurations carefully, including the scripts linked in the Tools section below. At a minimum, projects should move away from single verifier trust paths and aim for at least a 3 of N min_required_dvns configuration, with each validator controlled by an independent party. The Axie Infinity hack already taught this industry that a multisig is only as decentralized as the people and systems behind the keys.
If you are a node operator, you are now a legitimate target, especially in systems built on high trust assumptions. Attacks against RPC infrastructure have long been treated as mostly theoretical, but this appears to be the first major incident involving backdoored Geth nodes at scale. Keep that in mind and my Defcon talk on the subject as a useful reference:
Hyperbridge's Bad Joke
Hyperbridge joked on April 1 that it had been hacked. Two weeks later, $2.5M+ were stolen from the protocol. Attackers moved fast, exploiting a missing bounds check in a Merkle Mountain Range implementation that broke cross chain message verification.
The lesson here is timeless: in crypto, you do not get to joke about being hacked unless you have survived for a decade, stacked a dozen audits, and still do not mind daring fate. Even then, I would not risk it.
Kraken hit by Scattered Spider
Kraken suffered a data leak tied to malicious insiders on its customer support team. This is an identical incident to what happened to Coinbase last year, where multiple customer support representatives were bribed to reveal PII on high net worth individuals. The extortion playbook is the same so be on the lookout for highly targeted phishing attacks.
Vercel Data Leaked by Shiny Hunters
Vercel was hacked by ShinyHunters group with data already for sale on BreachForums. Defenders should rotate their keys, credentials, tokens and any other sensitive data that ever lived in Vercel. Be sure to also review any internal infrastructure, Github, deploy pipelines, etc. to look for possible backdoors.
Mass .fi Registrars Compromise
We now know how the recent wave of .fi domain hijacks happened: attackers social engineered the Finnish .fi registry, Traficom, to bypass protections many teams assumed front end registrars such as Gandi would provide. Until there is clear evidence that those controls have been hardened, .fi domains should be treated as elevated risk, especially for high value crypto infrastructure.
The attacker contacted Traficom impersonating a senior contributor related to CoW DAO, claiming that AWS/Gandi had refused to provide a transfer key. Traficom opened an investigation and requested clarifications from Gandi, which went unanswered past the April 7 deadline.
Incidents above were just a few of the most notable ones. There were also plenty of smart contract exploits, including the $18.4M Rhea Finance exploit on Near, the $1.9M Dango hack, and many others. There was even a $13.1M exchange hack, but who is counting at this point. You will find the details below.
It was a brutal week, the kind that leaves the ecosystem bruised and exhausted. But this space has always moved forward by studying failures, learning hard lessons, licking its wounds, and getting back to the work of defending the systems we care about.
Let’s dive into the news!
News
- Treasury Department announces crypto industry cyber threat sharing initiative.
- Circle hit with class action lawsuit over alleged inaction in $280 million Drift exploit.
- Bithumb turns to legal action to recover lost bitcoin in ‘fat finger’ incident. A 620,000 BTC oops.
- Drift Taps Tether for $148 Million Recovery Plan, Ditches Circle's USDC Following DeFi Exploit.
- Ethereum Foundation Opens $1M Fund To Cut Audit Costs.
- ETH Rangers Program Recap.
- Leading public good security with the ETH Rangers program by The Red Guild.
- Solidity Developer Survey 2025 Results.
- Acquittal For Storm? Breaking Down The Government's Exotic Theories.
- Q1 2026 Security & Compliance Report by Hacken.
- State-sponsored threats: Different objectives, similar access paths by Cisco Talos Intelligence.
- 2025 APT Report - Staying Ahead of the Modern Threat Landscape by TrendMicro.
Crime - Arrests and Seizures
- 'Operation Atlantic': US and UK Team With Firms to Trace, Freeze Millions in Stolen Crypto.
- British Scattered Spider hacker pleads guilty to crypto theft charges.
- Paraguay police confiscate coins from $1m teen crypto hacking gang.
- The fake website that led to an arrest: Inside the CoinDCX impersonation case.
- Rekt - Who Vets the Vetters?.
- Two U.S. nationals have been sentenced to 108 and 92 months in prison for running North Korean IT "laptop farms".
Crime - DPRK
- North Korea Laundered $1 Billion of Crypto in 4 Months. How Industry Leaders Can Change Crypto Freezes and Recovery by ZeroShadow.
- North Korea's Safari: Hunting for RATs by Mauro Eldritch (Bitso Quetzal Team).
- Kimsuky Deploys Malicious LNK Files to Implant Python-Based Backdoor in Multi-Stage Attack.
Crime - Wrench
Phishing
- Supply Chain Alert: Analyzing a Highly Sophisticated Fake Ledger Nano S+ Operation by Past_Computer2901.
- Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT by Elastic Security Labs.
- A total of $9.5M has been lost to a fake Ledger Live app on the Apple App Store, affecting 50+ victims across Solana, Bitcoin, Tron, and Ripple by Specter.
Scams
- ‘Crypto Robin Hood’ faked prison for clout, rugged memecoins for Palestine.
- A summary of the RAVE -95% price fluctuation from $26 to $1 over the past 24 hours by ZachXBT.
Malware
- CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace by Michael Clark (Sysdig).
Media
- Film Review: “Self Custody” Indie Film about Bitcoin on Amazon Prime.
- Dismantling "Fraud Factories". ChainPatrol Premieres "Lights in Dark Rooms" in Cannes.
- Sherlock - Web3 CISO Open Source Dilemma: Why AI May Force Code To Go Dark | Haim Krasniker.
- Immunefi - The AI Agent That Found a $100,000 Bug | Riptide (GregoAI).
Vulnerabilities
- Solana p-token: Catching a Bug Before Mainnet by Felix Wilhelm (Asymmetric Research).
- Relay Chain Vulnerability: False Validator Slashing Due to Proof Verification Bug by Wei Tang (sorpaas). Critical in Polkadot Relay Chain.
Research - AI
- A thread on lessons learned when building an AI auditor by Hari.
- TxRCA-Bench: Can AI Agents Identify the Root Cause of DeFi Exploits from On-Chain Data Alone? by Sahuang.
- These are the 2 skills I share with anyone I work with by forefy. Skill to ensure safe AI environment.
Research - Bug Hunting
- 94% of Long-Running Bug Bounty Programs On Immunefi Have Surfaced a Critical Vulnerability by Mitchell Amador.
- How I Broke my Starknet Staking Contract with Simple Math: A Lesson on Rounding Errors by rim dinov.
- How $40M Were Almost Stolen from Lazy Summer by blockful.
Research - Defense
- There’s more to security than audits by sujith.
- Dan's right answers for cybersecurity. Here are a few minimum viable security plans from Trail of Bits for your: Application, Corporate network, Personal security, Cryptocurrency, Sextortion, X Brand Account.
- The .fi Files: A Field Report on DNS Hijacking in DeFi by Chirag Agrawal.
- We beat Google’s zero-knowledge proof of quantum cryptanalysis by Trail of Bits.
- The Admin Audit Checklist by QuillAudits.
Research - EVM
- How Crypto Actually Works: The Missing Manual by Larry Cermak, Igor Igamberdiev (Wintermute), Bohdan Pavlov (Wintermute). A comprehensive technical book that explains how crypto actually functions, from Bitcoin's UTXO model to quantum-resistant cryptography. It spans 90,000+ words across 15 chapters plus a preface, covering everything from foundational concepts to new developments in the crypto ecosystem.
Research - Solana
- Solana Audit Arena — Week#3 — Zenon by Zuhaib Mohammed
Whitepapers
- Towards Adaptive, Learning-Based Security in Decentralized Applications.
- Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations.
- CKG-LLM: LLM-Assisted Detection of Smart Contract Access Control Vulnerabilities Based on Knowledge Graphs.
Tools
- safe-opensig by candidelabs. The Final Word for Multisig Signing. Stop crossing your fingers before every $1M signature. Safe OpenSig eliminates blind signing for signers who can't afford a mistake.
- vector by blueshift-gg. Offline Solana transaction signing without durable nonces.
- safe-tx-hashes-util-qubes by pcaversaccio. Qubes OS Environment for Safe Multisig Transaction Hashes.
- shipped some improvements for grimoire * auto load GRIMOIRE.md * improved triaging by familiar agent * automatic triaging of findings from sigils * small bugfix by Joran Honig.
- Multisig Security Checker by yAudit. Analyze your Safe multisig contract for security best practices. Enter an address to get started. More info in the blog.
- LayerZero OFT/OApp DVN configuration audit flags 1-of-N pathways. Released by Blockaid in the wake of the KelpDAO rsETH bridge incident (Apr 2026).
Hacks
Detailed indicators of compromise including exploit transactions, attacker address, exploit PoCs are available upon request.
Dango Compromise
Date: April 13, 2026
Attack Vector: Reward Manipulation
Impact: $1,900,000
Chain: Dango
https://x.com/dango/status/2043669424805216745
Hyperbridge Compromise
Date: April 13, 2026
Attack Vector: Signature Verification
Impact: $2,500,000
Chain: Ethereum, Base, BSC, Arbitrum
https://x.com/0xZilayo/status/2043546814037803401
Kraken Compromise 3
Date: April, 2026
Attack Vector: Unknown
Chain: Ethereum
https://x.com/c7five/status/2043720915330969743
TokenGateway Compromise
Date: April 13, 2026
Attack Vector: Unknown
Impact: $537,000
Chain: Ethereum
https://x.com/SpecterAnalyst/status/2043641769754235076
CowSwap DNS Compromise
Date: April 14, 2026
Attack Vector: DNS Hijacking
Chain: Ethereum
https://x.com/CoWSwap/status/2044924940886163780
MONA Compromise
Date: April 14, 2026
Attack Vector: Price Oracle Manipulation
Impact: $60,950
Chain: BSC
https://x.com/exvulsec/status/2043928546662592949
LootBot Compromise
Date: April 15, 2026
Attack Vector: Reward Manipulation
Impact: $9,600
Chain: Ethereum
https://x.com/DefimonAlerts/status/2044709964091187660
SquidMulticall Compromise
Date: April 16, 2026
Attack Vector: Arbitrary External Calls
Impact: $517,000
Chain: Arbitrum, BSC, Avalanche, Optimism, Base
https://x.com/Phalcon_xyz/status/2041463211493662942
Zerion Compromise 2
Date: April 16, 2026
Attack Vector: Hot Wallet Compromise
Impact: $100,000
Chain: Ethereum
https://x.com/zerion/status/2042713634686799885
Rhea Finance Compromise
Date: April 16, 2026
Attack Vector: Price Oracle Manipulation
Impact: $18,400,000
Chain: Near
https://x.com/Phalcon_xyz/status/2045728892489757098
Unkn_18d087 Compromise
Date: April 16, 2026
Attack Vector: Logic Error
Chain: Ethereum
https://x.com/audit_911/status/2045003195060265189
ListaDAOLiquidStakingVault
Date: April 16, 2026
Attack Vector: Unknown
Chain: Ethereum
https://x.com/audit_911/status/2044677392728510799
BTCN Compromise
Date: April 16, 2026
Attack Vector: Unknown
Chain: BSC
https://x.com/audit_911/status/2044672856097952193
Grinex (Garantex) Compromise
Date: April, 2026
Attack Vector: Unknown
Impact: $13,100,000
Chain: Ethereum
Eth Limo Compromise
Date: April 17, 2026
Attack Vector: DNS Hijacking
Chain: Ethereum
https://x.com/eth_limo/status/2045552916157563148
LayerZero KelpDAO Compromise
Date: April 18, 2026
Attack Vector: RPC Spoofing
Impact: $292,000,000
Chain: Ethereum
https://x.com/chrisgora/status/2045571572195291370
Vercel Compromise
Date: April 19, 2026
Attack Vector: Supply Chain
Chain: Ethereum