AI Summary
5 min readOn April 18, 2026, a DeFi exploit—widely attributed to North Korea's Lazarus Group—struck at the heart of crypto's composability stack. The attackers exploited LayerZero's cross-chain messaging protocol to mint 116,000 unbacked RS ETH tokens (Kelp DAO's liquid restaking token), deposited them into Aave V3 on Arbitrum and Ethereum mainnet, and borrowed $236 million in real ETH. The result was roughly $280 million in bad debt for Aave, triggering a bank run that saw $5 billion in ETH outflows and Aave's TVL plunge from $26 billion to $17 billion. In an unprecedented move, the Arbitrum Security Council used emergency powers to freeze and recover $70 million of the stolen funds—an action that has opened a deep philosophical rift about immutability, governance, and what users can actually expect from layer-two chains.
How the Exploit Worked: A Physics Event, Not a Ledger Error
Continue reading the full summary in the app — free to try.
Read Full Summary →Free • No credit card required
Never miss an episode of Bankless
Get every new episode summarized in your inbox — free, ~5 minutes to read.
No spam. Unsubscribe anytime.
What you'll learn
- 1 (00:00) **Crypto Hacks Are Physics Events** - Dan and Odysseus frame the core difference between TradFi and DeFi security: in TradFi you can reverse errors, in crypto the damage is irreversible.
- 2 (00:39) **Episode Setup: The $280M DeFi Exploit** - Hosts introduce the hack involving Kelp DAO, LayerZero, and Aave, and set up the significance of this event.
- 3 (02:55) **Why This Hack Is Different** - Dan explains why this exploit, though not the largest by dollar value, has outsized implications for DeFi's future.
- 4 (07:05) **How the Exploit Actually Worked** - Odysseus breaks down the technical mechanics of the attack at a high level.
- 5 (10:02) **Sophistication of the Attack** - Odysseus describes the advanced nature of the exploit, including evidence cleanup.
- 6 (11:55) **Explaining DeFi Hacks to Normies** - The hosts struggle to find simple analogies that make this exploit understandable to outsiders.
- 7 (16:32) **Who's Responsible? The Blame Game** - The panel dissects fault across LayerZero, Kelp DAO, and Aave.
+ Full timestamped outline available in the app
Show Notes
A $280M DeFi exploit exposed the hidden fragility of crypto’s most trusted systems.
Dan Elitzer and Odysseus break down how the attack happened, why bridge risk and protocol composability made the damage so severe, what Arbitrum’s intervention means for immutability, and why DeFi now needs an aerospace-grade security mindset to survive the AI era.
------
📣SPOTIFY PREMIUM RSS FEED | USE CODE: SPOTIFY24
https://bankless.cc/spotify-premium
------
🔮POLYMARKET | #1 PREDICTION MARKET
https://bankless.cc/polymarket-podcast
🦊 METAMASK | DOWNLOAD NOW
https://go.metamask.io/BL-Pod-Download
🌐BRIX | EMERGING MARKET YIELD
https://bankless.cc/brix
🧭OKX | TRADE, EARN, PAY
https://bankless.cc/OKX
💰NEXO | YIELD + CREDIT LINE
https://bankless.cc/nexo
🎯THE DEFI REPORT | ONCHAIN INSIGHTS
https://thedefireport.io/bankless
------
TIMESTAMPS
0:00 Intro
0:57 Worst DeFi Hack Ever?
7:01 What Happened?
10:11 How Sophisticated?
11:42 Explaining the Hack to TradFi
16:51 Who’s to Blame?
22:13 L2 Architecture Consequences
28:17 How Does it Get Resolved?
31:46 Circuit Breakers & Rate Limiters
34:05 AAVE V4
34:51 Arbitrum Intervention Implications
42:02 Code is Law vs Human Governance
51:59 Stage 1 vs Stage 2 Rollups
55:29 Post-Hack DeFi
1:03:05 Aerospace Level Security
1:09:49 Will DeFi Survive?
1:14:33 Closing & Disclaimers
------
RESOURCES
Dan Elitezer
Odysseus
Odyss
More from this podcast
Bankless →