
The hacker behind the Kelp DAO bridge exploit has moved nearly all unfrozen funds through privacy channels, leaving only a small balance in the original wallets. According to on-chain data cited by The Defiant, the funds moved through THORChain, Wasabi, Tornado Cash and Umbra, making direct tracking harder for investigators. The latest findings suggest only about $1.7 million remains in the original wallets, with the laundering process beginning shortly after the exploit. On-chain data shows the attackers transferred more than 75,000 ETH into newly created wallets before moving through multiple privacy-focused platforms and cross-chain services. The operation combined Bitcoin mixing services with Ethereum privacy tools, with THORChain reportedly processing unusually high volumes as the stolen assets moved across chains.
The April attack drained about $292 million from Kelp DAO's bridge, with Chainalysis reporting that the attackers released about 116,500 rsETH against a fake burn event after targeting off-chain bridge infrastructure. As reported by LayerZero's incident report, the attack was linked to TraderTraitor, a North Korea-linked group also tracked as UNC4899 and part of the wider Lazarus ecosystem. The same threat network has been tied to other large crypto attacks this year, including the $577 million theft from Drift Protocol and KelpDAO in April. Security researchers linked the attack to TraderTraitor, a North Korean cyber group that has previously been associated with several major crypto thefts.
A large part of the stolen assets did not move freely after the attack, with Arbitrum's Security Council freezing more than 30,000 ETH soon after the exploit. According to The Defiant, the frozen portion is about $71 million and is now tied to legal claims in the U.S., after families with unpaid judgments against North Korea sought control of the funds. The remaining unfrozen funds have largely moved through privacy tools, creating challenges for direct recovery through normal address-by-address tracing. However, those assets are now tied up in ongoing legal proceedings, with families holding terrorism judgments against North Korea also filing claims related to the frozen funds, making the final outcome uncertain.
The case adds pressure on bridge operators, DeFi teams and investigators to act before stolen funds enter privacy routes. As previously reported by crypto.news, North Korea-linked Lazarus attacks drained $577 million from Drift Protocol and KelpDAO in April, making up 76% of all crypto theft tracked in 2026 through April. The incident serves as another reminder that bridge security remains one of the industry's biggest challenges, with developers and investors alike demanding stronger safeguards across blockchain infrastructure. The growing involvement of state-sponsored groups raises concerns about future recovery efforts, as once stolen assets move through multiple chains and privacy services, recovering funds becomes significantly harder. The Kelp DAO case may become one of the defining bridge exploits of 2026, highlighting the broader impact of sophisticated attack patterns on the crypto ecosystem.