
According to reports from crypto.news, Lido Labs has requested the Lido DAO to approve the allocation of up to 2,500 stETH, worth approximately $5.8 million, to address the rsETH shortfall caused by the recent Kelp exploit. The proposal, titled "Lido DAO Contribution to Coordinated rsETH Relief Effort," emphasizes that these funds would not serve as a full bailout but would be part of a coordinated recovery package designed to close the rsETH deficit in full. As reported by crypto.news, the proposal states that "Kelp's rsETH LayerZero exploit created a material rsETH backing shortfall with broader second-order effects across integrated DeFi venues," placing pressure on market rates, lending positions, and vault users. The proposal caps the contribution at $5.8 million worth of stETH, with the final amount potentially lower depending on contributions from other participating protocols or revised assessment of the total shortfall.
The proposal follows a roughly $293 million exploit that targeted Kelp DAO's rsETH bridge last week, creating stress across connected DeFi platforms and raising concerns over bad debt. According to Lookonchain analysis reported by crypto.news, the attack created approximately $195 million in bad debt and left about $195 million in bad debt. The full deficit is estimated to exceed 100,000 ETH, requiring multiple contributors to fund the recovery effort. The attack reportedly affected the protocol's rsETH bridge and involved 116,500 rsETH, equal to about 18% of circulating supply. Lido Labs stated that given the deficit's size, this recovery vehicle is expected to include multiple contributors, with Lido DAO participating as one of several stakeholders rather than as the sole backstop provider. An incident report published on Aave's governance forum dated April 20, 2026, details the event that created the shortfall, with Aave publishing a formal incident report underscoring the severity of the situation and its cross-protocol impact.
The Kelp exploit represents part of a broader wave of DeFi attacks that have collectively resulted in over $600 million in total losses across recent incidents. As reported by AMBCrypto, the attacker drained 75,701 ETH worth $175 million from their holdings before converting funds into Bitcoin through THORChain, highlighting how quickly stolen assets can move across DeFi infrastructure. In response to the incident, Mantle proposed a 30,000 ETH ($70 million) loan to Aave to help contain liquidity stress and stabilize market conditions. According to AMBCrypto analysis, the $15 billion TVL outflows reflect more than temporary panic selling, potentially signaling a deeper structural shift in how capital reacts to DeFi risks. Bobby Gray, CEO and co-founder of TEXITcoin, told AMBCrypto that the attacks show how "complex DeFi systems have become, with risk spread across multiple layers like bridges and verification networks," pushing crypto further away from its original principles of transparency, simplicity, and direct participation.
The proposal remains subject to Lido DAO governance approval, with a related on-chain vote (Vote #200) posted to Lido's governance portal, indicating the proposal has moved beyond the discussion phase into formal consideration. If approved, up to $5.8 million in stETH would be directed toward the relief effort. The "up to" language in the proposal suggests the final amount could be lower depending on contributions from other participating protocols or a revised assessment of the total shortfall. If rejected or revised, Kelp DAO and other stakeholders would need to find alternative sources to cover the gap, potentially meaning larger contributions from other protocols, a longer timeline for affected users to be made whole, or a restructured repayment plan.
The Kelp exploit has renewed debate about DeFi platform security and risk management, with industry analysts drawing parallels to the 2008 financial crisis. According to a DeFi-focused account analysis, the incident shows how "stacking asset layers does not remove risk. It compresses and hides it." The analysis compared the structure to mortgage products before the 2008 crisis, noting that rsETH moved through several layers before the exploit - users first staked ETH through Lido and received stETH, which could then move into Kelp DAO and EigenLayer, where rsETH was minted, before being used as collateral on lending platforms such as Aave, SparkLend, and Fluid. The post argued that each layer adds new risks, including validator slashing, restaking risks, bridge bugs, contract failures, and lending liquidations. It questioned bridge security, claiming Kelp used a 1-of-1 verifier setup, meaning one node verified cross-chain messages before funds moved, creating a single point of failure inside a product marketed as decentralized. The incident has become part of a wider debate on DeFi security, leverage, and transparency, showing how one failure can affect users across several platforms, including users who did not directly interact with Kelp DAO.