Over $300M was drained across four incidents between April 13 and April 18, 2026: a cross-chain bridge exploit on KelpDAO that routed funds through Tornado Cash, an oracle manipulation draining Rhea Finance on NEAR, a DNS hijacking of the CoW Swap front-end, and a forged cross-chain message that minted 1 billion bridged DOT tokens on Ethereum.
This week’s Recoveris report covers the KelpDAO rsETH bridge drain that became the largest DeFi exploit of 2026 and triggered contagion across Aave, the Rhea Finance oracle manipulation that extracted stablecoins and NEAR, the DNS hijack that redirected CoW Swap users to a wallet-drainer site, and the Hyperbridge vulnerability that allowed an attacker to mint 1 billion bridged DOT but liquidate only a fraction.
KelpDAO – ~$292,000,000 | April 18, 2026 | Multi-chain
On April 18 at 17:35 UTC, an attacker sent a crafted cross-chain message to KelpDAO’s LayerZero-powered bridge, which accepted it as legitimate and released 116,500 rsETH to an attacker-controlled wallet. The drain totaled approximately $292 million and represented roughly 18% of rsETH’s circulating supply. Kelp’s emergency pauser multisig froze the protocol’s core contracts 46 minutes after the drain completed.
The bridge’s verifier configuration required only one DVN attestation with no backup validators, meaning a single forged message path was sufficient to authorize the release. The attacker wallet had been funded through Tornado Cash ten hours earlier, and roughly $250 million of the stolen assets were swapped to ETH in the hours following the exploit. rsETH had active exposure across approximately 20 chains, leaving wrapped tokens stranded and creating fragmented recovery paths.
The contagion extended beyond KelpDAO. Aave was left carrying over $200 million in bad debt after attackers used drained rsETH as collateral to borrow wrapped ether, and DeFi TVL dropped roughly $13 billion in the 48 hours following the incident. When a bridge exploit of this magnitude intersects with lending markets, tracing and freezing must be coordinated across multiple protocol teams, exchanges, and mixer exit points simultaneously. The Tornado Cash funding trail is a narrow but viable investigative lead.
Sources: Cointelegraph, CoinDesk
Rhea Finance – ~$7,600,000 | April 16, 2026 | Smart Contract
On April 16, an attacker drained approximately $7.6 million from Rhea Finance, the NEAR DeFi protocol formed from the 2025 merger of Ref Finance and Burrow Finance. Stolen assets included USDC, USDT, ZEC, and NEAR. The Rhea team paused all contracts immediately after the breach was confirmed.
The attack relied on deploying fake token contracts and seeding artificial liquidity pools to manipulate the protocol’s oracle. By flooding new pools with fake tokens and real collateral, the attacker created a convincing but synthetic price feed that the oracle accepted, allowing the fake tokens to be used as collateral to borrow real assets. The approach only requires enough price history for the oracle to treat the feed as valid, which is a low bar for newly deployed pools.
Tether subsequently froze approximately $3.29 million in USDT linked to the attacker. Oracle manipulation exploits typically leave recoverable footprints at centralized exit points. Stablecoin issuers and CEX compliance teams can act quickly when funds are flagged within hours of the incident, which makes fast forensic intake and direct coordination with issuers the decisive factor in how much of the loss is ultimately frozen.
Sources: Halborn, Crypto Times
CoW Swap – ~$500,000 | April 14, 2026 | Front-end
On April 14 at 14:54 UTC, attackers hijacked the DNS for CoW Swap’s front-end at swap.cow.fi, redirecting visitors to a malicious phishing site for more than 90 minutes. Web3 security firm Blockaid flagged the compromised domain, and the CoW DAO team paused protocol APIs and backend services as a precaution. Estimated user losses totaled approximately $500,000, with at least one individual reporting losses above $50,000.
The malicious site served a wallet-drainer script that prompted users to sign limitless spend permissions under the guise of a protocol update, with the script specifically targeting high-value tokens like USDC and WETH. The CoW Protocol smart contracts and backend APIs were confirmed unaffected. The attack surface was the front-end interface alone, but the consequences for users interacting during the window were identical to any on-chain exploit.
Front-end DNS hijacking is a growing vector because it bypasses smart contract audits entirely. Recovery depends on rapid tracing of the consolidation wallets and coordination with exchanges before attackers convert or bridge the assets. Retail victims of wallet-drainer scripts rarely pursue tracing individually, which makes coordinated action by the affected protocol an important recovery lever.
Hyperbridge (Bridged DOT) – ~$237,000 | April 13, 2026 | Multi-chain
On April 13, an attacker exploited a vulnerability in Hyperbridge’s Ethereum gateway contract to mint 1 billion bridged DOT tokens. The theoretical value of the mint was over $1.1 billion, but shallow liquidity in the Ethereum DOT pool limited realized proceeds to approximately $237,000 in ETH after the tokens were dumped.
A forged cross-chain message bypassed the state proof validation path on the bridge contract, granting the attacker admin control over the bridged DOT token. The request receipts check, which should have verified the message against a valid cross-chain state commitment from Polkadot, recorded an all-zeros commitment value. This indicates the proof validation was either absent or circumventable for this specific call path. The exploit did not affect Polkadot’s native network or native DOT.
Upbit and Bithumb suspended DOT deposits and withdrawals on April 13, citing liquidity risk to users. The incident illustrates a recurring pattern in bridge security: proof-check gaps that remain latent until an attacker finds the specific call path that evades them. Higher-value deployments with the same class of vulnerability would produce losses orders of magnitude larger than this one.
If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.