BlockThreat - Week 16, 2026

KelpDAO suffers the biggest hack of the year, Hyperbridge gets caught by its own joke. 17 incidents, $329M in losses, and many harsh lessons for bridges, node operators, and DeFi teams still relying on broken trust models.

BlockThreat - Week 16, 2026

Never a dull day in crypto. Just two weeks after AppleJeus hit Drift Protocol, another elite North Korean crew, TraderTraitor, pulled off an even bigger and more sophisticated operation against KelpDAO through LayerZero. Hyperbridge made an April 1 joke about getting hacked only to get hacked for real two weeks later. All told, the week ended with 17 incidents and $329,124,550 in losses. In this edition, we break down the KelpDAO and LayerZero disaster, multiple CeFi exchange incidents and threat actors behind them, and the other major compromises that made this one of the most painful weeks of the year.

Paid subscribers can read on for the full breakdown of the KelpDAO and LayerZero hack, incident response lessons, infrastructure failures, and the complete roundup of this week’s hacks, phishing and malware campaigns, research, tools, and other essential threat intelligence.

KelpDAO / LayerZero Incident

Let’s start with the biggest hack of the year and one of the clearest reminders to review your protocol's trust assumptions. On April 18, DPRK's TraderTraitor threat actor drained $292 million from KelpDAO by forging LayerZero messages for rsETH, stealing 116,500 rsETH in the process. LayerZero’s preliminary account points to a highly sophisticated operation that poisoned RPC infrastructure relied on by the DVN and exploited KelpDAO’s single DVN setup to push through fake attestations.

As is usual with incidents of this size, the damage did not stop at the bridge. The stolen rsETH was quickly pushed into Aave and used to borrow ETH before the market could fully contain the damage. Depending on how losses are socialized, Aave’s bad debt exposure is being modeled in a range of roughly $124 million to $230 million. In other words, one weak trust path on one bridge was enough to spill directly into the balance sheet of a $16B lending protocol. And then came the second order damage. Once the market understood the scope of the exploit, liquidity fled often at a loss. Whales rushed to unwind risk, DeFi protocols scrambled through emergency responses.

The finger pointing started almost immediately. KelpDAO says the story is bigger than a bad app level setting. LayerZero says the hack was made possible by KelpDAO’s 1 of 1 DVN configuration. Both things can be true. Just like with the Bybit/Safe hack, TraderTraitor found a way to compromise critical infrastructure and then picked the juiciest target. The problem was not just one bad setting, but a combination KelpDAO's misplaced trust into LayerZero's infrastructure which happily printed hundreds of millions without any circuit breakers or reviews until it was too late.

That is also why this incident should make the rest of DeFi uncomfortable. According Dune's recently published dataset, 589 projects have at least one path where `min_required_dvns = 1. That's roughly half of all projects! KelpDAO was the name on the headline, but any one of those projects could have been targeted as well causing a massive meltdown.

There are at least two bright spots. First, KelpDAO was able to respond fairly fast (about 1 hour) to halt the second exploit transaction that would have drained another $100M.

Second, after the attackers moved funds onto Arbitrum and left them there for the weekend, the Arbitrum Security Council took emergency action and clawed back 30,766 ETH, about $71 million tied to the exploit. Decisive intervention like that remains rare in this industry. It should not be controversial to say that this was the right move. This is to the stark contrast to Circle's actions in the recent Drift compromise which simply refuses to freeze well known attacker funds and is now getting sued for it. As one one member of the Arbitrum Security Council put it:

This stands in stark contrast to Circle’s response during the Drift compromise, where the company refused to freeze well known attacker funds and is now being sued over it. As one member of the Arbitrum Security Council put it:

While we wait for comprehensive post-mortems, there are already a few high level lessons that similar projects should adopt.

  • Threat model your trust assumptions, identify weak points, and build mitigations around them. This should be standard practice, yet too many teams still stop at the audit checkbox and walk away with a false sense of security.
  • Chains, bridges, and major DeFi operators should have incident response plans and playbooks ready to freeze attacker funds quickly when needed. Save the cypherpunk ideals for a world where the money flowing through your protocol cannot be used to fund ICBMs.

On the technical side, bridge operators review your DVN configurations carefully, including the scripts linked in the Tools section below. At a minimum, projects should move away from single verifier trust paths and aim for at least a 3 of N min_required_dvns configuration, with each validator controlled by an independent party. The Axie Infinity hack already taught this industry that a multisig is only as decentralized as the people and systems behind the keys.

If you are a node operator, you are now a legitimate target, especially in systems built on high trust assumptions. Attacks against RPC infrastructure have long been treated as mostly theoretical, but this appears to be the first major incident involving backdoored Geth nodes at scale. Keep that in mind and my Defcon talk on the subject as a useful reference:

Hyperbridge's Bad Joke

Hyperbridge joked on April 1 that it had been hacked. Two weeks later, $2.5M+ were stolen from the protocol. Attackers moved fast, exploiting a missing bounds check in a Merkle Mountain Range implementation that broke cross chain message verification.

The lesson here is timeless: in crypto, you do not get to joke about being hacked unless you have survived for a decade, stacked a dozen audits, and still do not mind daring fate. Even then, I would not risk it.

Kraken hit by Scattered Spider

Kraken suffered a data leak tied to malicious insiders on its customer support team. This is an identical incident to what happened to Coinbase last year, where multiple customer support representatives were bribed to reveal PII on high net worth individuals. The extortion playbook is the same so be on the lookout for highly targeted phishing attacks.

Vercel Data Leaked by Shiny Hunters

Vercel was hacked by ShinyHunters group with data already for sale on BreachForums. Defenders should rotate their keys, credentials, tokens and any other sensitive data that ever lived in Vercel. Be sure to also review any internal infrastructure, Github, deploy pipelines, etc. to look for possible backdoors.

Mass .fi Registrars Compromise

We now know how the recent wave of .fi domain hijacks happened: attackers social engineered the Finnish .fi registry, Traficom, to bypass protections many teams assumed front end registrars such as Gandi would provide. Until there is clear evidence that those controls have been hardened, .fi domains should be treated as elevated risk, especially for high value crypto infrastructure.

The attacker contacted Traficom impersonating a senior contributor related to CoW DAO, claiming that AWS/Gandi had refused to provide a transfer key. Traficom opened an investigation and requested clarifications from Gandi, which went unanswered past the April 7 deadline.

Incidents above were just a few of the most notable ones. There were also plenty of smart contract exploits, including the $18.4M Rhea Finance exploit on Near, the $1.9M Dango hack, and many others. There was even a $13.1M exchange hack, but who is counting at this point. You will find the details below.

It was a brutal week, the kind that leaves the ecosystem bruised and exhausted. But this space has always moved forward by studying failures, learning hard lessons, licking its wounds, and getting back to the work of defending the systems we care about.

Let’s dive into the news!

News

Crime - Arrests and Seizures

Crime - DPRK

Crime - Wrench

Phishing

Scams

Malware

Media

Vulnerabilities

Research - AI

Research - Bug Hunting

Research - Defense

Research - EVM

  • How Crypto Actually Works: The Missing Manual by Larry Cermak, Igor Igamberdiev (Wintermute), Bohdan Pavlov (Wintermute). A comprehensive technical book that explains how crypto actually functions, from Bitcoin's UTXO model to quantum-resistant cryptography. It spans 90,000+ words across 15 chapters plus a preface, covering everything from foundational concepts to new developments in the crypto ecosystem.

Research - Solana

Whitepapers

Tools

Hacks

Detailed indicators of compromise including exploit transactions, attacker address, exploit PoCs are available upon request.

Dango Compromise

Date: April 13, 2026
Attack Vector: Reward Manipulation
Impact: $1,900,000
Chain: Dango

https://x.com/dango/status/2043669424805216745

Hyperbridge Compromise

Date: April 13, 2026
Attack Vector: Signature Verification
Impact: $2,500,000
Chain: Ethereum, Base, BSC, Arbitrum

https://x.com/0xZilayo/status/2043546814037803401

Kraken Compromise 3

Date: April, 2026
Attack Vector: Unknown
Chain: Ethereum

https://x.com/c7five/status/2043720915330969743

TokenGateway Compromise

Date: April 13, 2026
Attack Vector: Unknown
Impact: $537,000
Chain: Ethereum

https://x.com/SpecterAnalyst/status/2043641769754235076

CowSwap DNS Compromise

Date: April 14, 2026
Attack Vector: DNS Hijacking
Chain: Ethereum

https://x.com/CoWSwap/status/2044924940886163780

MONA Compromise

Date: April 14, 2026
Attack Vector: Price Oracle Manipulation
Impact: $60,950
Chain: BSC

https://x.com/exvulsec/status/2043928546662592949

LootBot Compromise

Date: April 15, 2026
Attack Vector: Reward Manipulation
Impact: $9,600
Chain: Ethereum

https://x.com/DefimonAlerts/status/2044709964091187660

SquidMulticall Compromise

Date: April 16, 2026
Attack Vector: Arbitrary External Calls
Impact: $517,000
Chain: Arbitrum, BSC, Avalanche, Optimism, Base

https://x.com/Phalcon_xyz/status/2041463211493662942

Zerion Compromise 2

Date: April 16, 2026
Attack Vector: Hot Wallet Compromise
Impact: $100,000
Chain: Ethereum

https://x.com/zerion/status/2042713634686799885

Rhea Finance Compromise

Date: April 16, 2026
Attack Vector: Price Oracle Manipulation
Impact: $18,400,000
Chain: Near

https://x.com/Phalcon_xyz/status/2045728892489757098

Unkn_18d087 Compromise

Date: April 16, 2026
Attack Vector: Logic Error
Chain: Ethereum

https://x.com/audit_911/status/2045003195060265189

ListaDAOLiquidStakingVault

Date: April 16, 2026
Attack Vector: Unknown
Chain: Ethereum

 https://x.com/audit_911/status/2044677392728510799

BTCN Compromise

Date: April 16, 2026
Attack Vector: Unknown
Chain: BSC

https://x.com/audit_911/status/2044672856097952193

Grinex (Garantex) Compromise

Date: April, 2026
Attack Vector: Unknown
Impact: $13,100,000
Chain: Ethereum

https://archive.ph/jRLSV

Eth Limo Compromise

Date: April 17, 2026
Attack Vector: DNS Hijacking
Chain: Ethereum

https://x.com/eth_limo/status/2045552916157563148

LayerZero KelpDAO Compromise

Date: April 18, 2026
Attack Vector: RPC Spoofing
Impact: $292,000,000
Chain: Ethereum

https://x.com/chrisgora/status/2045571572195291370

Vercel Compromise

Date: April 19, 2026
Attack Vector: Supply Chain
Chain: Ethereum

https://x.com/DiffeKey/status/2045813085408051670