Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

KelpDAO Cross-Chain Bridge Vulnerability: $290 Million in DeFi Assets Frozen Due to AI-Automated Governance Exploits

Victims are primarily DeFi liquidity providers and retail investors who were attracted by KelpDAO's high-yield staking schemes and deposited assets into pools linked to the cross-chain bridge. Most victims lacked the expertise to audit the underlying code and governance structures of the bridge, mistakenly believing that audited protocols were inherently secure. Their psychological vulnerability stemmed from over-reliance on audit reports and brand endorsements, leading them to ignore risks associated with governance flaws and exposed multi-sig permissions, ultimately resulting in their assets being frozen or wiped out during the attack.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are primarily DeFi liquidity providers and retail investors who were attracted by KelpDAO's high-yield staking schemes and deposited assets into pools linked to the cross-chain bridge. Most victims lacked the expertise to audit the underlying code and governance structures of the bridge, mistakenly believing that audited protocols were inherently secure. Their psychological vulnerability stemmed from over-reliance on audit reports and brand endorsements, leading them to ignore risks associated with governance flaws and exposed multi-sig permissions, ultimately resulting in their assets being frozen or wiped out during the attack.

骗局怎么运作

  • Step 1: Attackers use AI programming agents to automatically scan the smart contract code of the KelpDAO and LayerZero cross-chain bridge, focusing on vulnerabilities in governance permissions, multi-sig wallet addresses, and cross-chain message verification logic, replacing manual audits with high-speed, batch-processed detection.
  • Step 2: The AI tool identifies flaws in cross-chain message verification and uses forged cross-chain messages to deceive contracts on the target chain, allowing attackers to trigger asset transfers or freezing operations as a legitimate entity, thereby bypassing multi-sig permission restrictions.
  • Step 3: Attackers amplify the scale of the attack through flash loans and multiple cross-chain hops, transferring large amounts of assets from the liquidity pool to attacker-controlled addresses in a short period, while triggering the protocol's security mechanisms to freeze remaining assets. On-chain data indicates losses of approximately $290 million.
  • Step 4: Upon discovering the anomaly, the project team urgently suspended the contracts, but the assets had already been siphoned off. The team attempted to recover funds via governance proposals, but because multi-sig permissions had been bypassed, no remedial actions could be executed, causing a collapse in DeFi market confidence and a TVL drop of over $20 billion.
  • Step 5: Attackers laundered the stolen funds using coin-mixing services and cross-chain bridges. Affected users were unable to withdraw remaining assets due to the contract freeze, and while some sought collective legal action, it proved futile. The incident became a landmark case in the 2026 DeFi security crisis.

红旗信号(看到这些快跑)

  • 🚩 The project claims to use AI for market-making or risk management but fails to disclose verifiable code audit reports or AI model details, using marketing buzzwords to attract deposits.
  • 🚩 The protocol's multi-sig permissions are concentrated in a few addresses without public disclosure of the holders, allowing any governance proposal to be manipulated by a small number of accounts.
  • 🚩 The cross-chain bridge relies on too few verification nodes or has a single point of failure, making it unable to withstand malicious message injection attacks.
  • 🚩 The official community is slow to respond to security incidents, suspending trading before disclosing information, leaving users unable to withdraw funds in time.
  • 🚩 The governance token distribution mechanism is abnormal, with rewards concentrated in early whale addresses, leaving ordinary users to bear the risks without actual governance power.

真实案例

  • In April 2026, the KelpDAO and LayerZero cross-chain vulnerability was exploited by AI tools, causing approximately $290 million in losses and freezing the DeFi market. The incident was disclosed by Galaxy Research in an infrastructure-themed report, with analysis published on Blockweeks news. (Source: https://blockweeks.com/news/315194)
  • In May 2026, according to an NS3.AI report, DeFi protocols lost over $840 million to hacker attacks in the first five months of the year, with April alone accounting for $635 million across 28 incidents, with AI programming agents serving as the primary attack tool.
  • The Lazarus Group successfully breached both Drift Protocol and KelpDAO in 2026. In the KelpDAO incident, attackers used AI to automatically discover governance logic vulnerabilities in the cross-chain bridge. Gate blog provided a dedicated analysis, noting that DeFi TVL plummeted by over $20 billion as a result.
  • According to data from blockchain analytics firm TRMLabs, North Korea-linked hacker groups have stolen approximately $577 million, including two major attacks on KelpDAO (approx. $292 million) and Drift Protocol (approx. $285 million). These two attacks accounted for approximately 76% of global crypto theft losses in 2026. (Source: https://www.chaincatcher.com/article/2262404)

Official Stance

  • In May 2026, the official Binance community released a report noting that DeFi protocols suffered over $840 million in hacker attacks in early 2026, warning users to be vigilant against AI-driven attack vectors.
  • In May 2026, Gate blog published 'AI-Driven DeFi Security Crisis: 2026 $1.1 Billion Hacker Loss and Attack Vector Analysis,' warning of the risks of AI agents exploiting governance vulnerabilities.
  • In April 2026, AiCoin published 'How to Choose Safe and Reliable DeFi Protocols in 2026,' emphasizing that regulatory policies focus on governance rules, multi-sig permissions, and cross-chain bridge mechanisms, while reminding users of the risks of signature leakage.

How to Protect Yourself

  • ✅ Before participating in any DeFi protocol, independently verify multi-sig address holder information and the thresholds for executing governance proposals; avoid projects with overly concentrated permissions.
  • ✅ Remain vigilant against protocols claiming to be AI-driven; demand that the project team disclose AI model audit results and third-party security verification reports, and do not blindly trust marketing rhetoric.
  • ✅ Use non-custodial wallets and set up separate hardware wallets for offline storage of large assets; avoid locking all funds into cross-chain bridges or liquidity pools.
  • ✅ Monitor official protocol Twitter accounts and security monitoring platforms (such as Chainalysis or TRM Labs) for alerts, and withdraw funds immediately if governance anomalies or surges in cross-chain activity are detected.