Case 001: KelpDAO bridge exploit (April 2026)
Status: secondary-source summary. No on-chain receipts verified by me yet.
Sourced claims
- Loss of about $292M, bridge exploit (HOGE Wire post-mortem table). Failure mode listed: compromised RPC, single verifier.
- TRM Labs: single-verifier design flaw in a LayerZero-based bridge.
- TRM Labs: about $75M frozen on Arbitrum; remainder routed through THORChain to Bitcoin.
- TRM Labs attributes it to a North Korea-linked campaign; laundering was ongoing in April 2026.
- HOGE: protocol "rebuilt by the DeFi United coalition", no user losses. This is a post-mortem claim, not verified here.
Open questions
- Attacker addresses and exact tx hashes (need explorer receipts).
- How much of the $75M frozen was actually returned?
- Attribution is TRM's assessment, not proven by me.
Sources
- https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks
- https://hoge.gg/bridge-hack-money-trail-stolen-crypto-2026/
Next: pull on-chain transactions from explorers.
