TL;DR:
- The hacker behind the $293 million Kelp DAO exploit laundered practically $220 million in stolen funds in simply six weeks.
- The funds had been laundered in two phases: first by means of the Wasabi mixer into Bitcoin, then again to Ethereum through Twister Money.
- A complete of $71 million stays frozen by the Arbitrum Safety Council. A courtroom listening to in New York remains to be pending.
The hacker answerable for the Kelp DAO exploit of $293 million managed to launder roughly $220 million in stolen funds in simply six weeks, in accordance with information from Arkham and onchain analysts. The pockets linked to the attacker holds simply $1.7 million in traceable funds, drastically decreasing the possibilities of recovering the non-frozen property.
In accordance with onchain analyst Specter, the laundering course of was executed in two phases. First, the funds had been transferred to Bitcoin by means of the Wasabi mixer to obscure their path. They then returned to the Ethereum community and had been processed by means of the Twister Money protocol. This sequence was designed to make the property nearly unimaginable to hint.

Decision on the Frozen Funds
The unique exploit occurred on April 18, when the attacker stole 116,500 rsETH tokens from Kelp DAO, bringing the overall losses from hacks in April to $630 million. Three days later, the Arbitrum Safety Council froze $71 million of these funds. A governance proposal and a U.S. courtroom order had beforehand permitted the switch of these property to a multisig pockets managed by Aave as a part of the restoration course of. The following listening to on the possession of the frozen funds is scheduled for this Friday in New York.
The Affect of the Kelp DAO Exploit
The assault generated penalties that unfold throughout all the DeFi ecosystem. Losses from exploits in cryptocurrencies dropped to $68.3 million in Could, a discount of practically 90% in comparison with April, in accordance with safety platform CertiK. Nevertheless, the Kelp DAO incident prompted a number of protocols to overview the safety of their oracle suppliers.


Within the three weeks following the exploit, Solv Protocol and liquidity protocol Tydro migrated to Chainlink‘s cross-chain interoperability protocol (CCIP). Kelp DAO itself additionally migrated its rsETH token to Chainlink CCIP, transferring away from the LayerZero-based bridge it attributed the exploited vulnerability to.
LayerZero, for its half, clarified that the exploit originated in a single level of failure in Kelp DAO’s implementation, which relied on a single LayerZero DVN as the only real verified route, regardless of warnings issued in opposition to that configuration.