# Ketju research: Kelp DAO (rsETH)

- URL: https://riadefi.com/rejections/kelp/
- Research assessment: adverse
- Client selection: not considered
- Exposure: ETH staking
- Reviewed: 2026-07-31
- Next review: 2027-07-31

## Research summary

ADVERSE RESEARCH ASSESSMENT AFTER A REALIZED CONTROL FAILURE. On 2026-04-18, a forged cross-chain packet released 116,500 rsETH, worth about $292M at the time, from Kelp's Ethereum LayerZero adapter without a corresponding source-side burn. The old memo's “$196M of Aave bad debt” was not a settled figure: Aave service providers initially modeled multiple loss-allocation scenarios, and the recovery changed them. LayerZero's final report says the application owner had changed a prior 2-of-2 verification setup to a single 1-of-1 DVN; compromise of LayerZero internal RPC infrastructure plus denial of service against a third-party RPC was then sufficient. Mainnet restaking contracts and EigenLayer deposits were not exploited, but the bridge was part of the rsETH product and its weakest configuration governed holder solvency. An ecosystem recovery ultimately restored backing, while Kelp retired bridging on 19 networks and left stranded holders a manual, quarterly recovery path. Recovery is positive conduct, not evidence the original control was acceptable. The v1 rejection remains.

## Observable review triggers

- Any contract, oracle, interface, bridge or backing impairment during the 24-month reopening observation period
- Any supported bridge using a single verifier, single provider, or configuration change without an enforced exit delay
- Any issued rsETH not continuously covered by independently verifiable backing
- Any unapproved LST, EigenLayer operator, AVS, oracle, or cross-chain deployment entering the risk set
- Proposed-size mainnet withdrawal or market exit exceeding the written timing or slippage limit

---

Published by Ketju Research (https://ketjuresearch.com). Educational analysis only; not legal, tax, compliance, or investment advice.
Machine-readable index: https://riadefi.com/llms.txt · Content API: https://riadefi.com/content.json
