Ethereum’s Kelp DAO Leads $940M H1 Crypto Exploit Losses

ETH

ETH/USDT

$1,865.91
-1.01%
24h Volume

$7,046,255,955.54

24h H/L

$1,890.61 / $1,848.70

Change: $41.91 (2.27%)

Long/Short
68.1%
Long: 68.1%Short: 31.9%
Funding Rate

+0.0003%

Longs pay

Data provided by COINOTAG DATALive data
Ethereum
Ethereum
Daily

$1,867.68

0.27%

Volume (24h): -

Resistance Levels
Resistance 3$2,063.38
Resistance 2$1,981.24
Resistance 1$1,902.99
Price$1,867.68
Support 1$1,809.40
Support 2$1,778.76
Support 3$1,722.34
Pivot (PP):$1,882.48
Trend:Sideways
RSI (14):51.3
(11:04 AM UTC)
4 min read
AI SummaryAI
  • ack3 recorded 135 crypto exploits between January and June, totaling $939.86 million in losses.
  • Ethereum-linked Kelp DAO rsETH lost $292 million after a forged LayerZero cross-chain message.
  • Solana derivatives platform Drift lost $285 million after attackers obtained administrative keys.
  • Audited projects lost $681 million through attack paths outside reviewed scope, equal to 94% of their losses.

This summary was AI-generated, AI-reviewed and published under COINOTAG editorial oversight.

Crypto News

Ethereum (ETH) faced the largest single security failure in the first half of 2026 when Kelp DAO’s rsETH, a liquid restaking token tied to Ethereum staking yields, lost $292 million after attackers forged a LayerZero cross-chain message. The incident was the biggest of 135 exploits recorded between January and June by security researcher ack3, whose public dataset attributes $939.86 million in total crypto losses to compromised keys, infrastructure, and message-validation weaknesses. The average incident cost about $6.96 million, but the damage was concentrated in two events that together represented roughly 61% of half-year losses. Among losses tied to projects that had undergone at least one review, 94.4% exited through components outside the audit’s declared scope, according to the dataset. That gap turns a widely used trust signal into a narrow attestation, not a broad guarantee of operational safety. Kelp’s failure came from a single verifier with no backup checkpoint, showing how cross-chain architecture can turn one weak integration into a system-wide drain. Two weeks earlier, Solana derivatives platform Drift lost $285 million after operatives linked by researchers to North Korea spent months obtaining administrative keys. Those cases underline that the most expensive attacks did not break core cryptographic math; they broke operational trust. Smaller exploits followed the same pattern, including $40 million from Step Finance, $32 million from Humanity Protocol, and $24.5 million from Resolv’s USR stablecoin. Cross-chain bridges also repeated as targets, with Verus losing $11.5 million, Syscoin $8 million, and Taiko $1.7 million. Even well-known platforms were affected: Polymarket suffered a $700,000 internal-wallet drain in May and a $3.1 million front-end supply-chain attack in June, while automated trading strategies, a category covered in our AI trading bot glossary, were exposed when jaredfromsubway.eth lost $7.5 million through a honeypot token. For holders of any altcoin, the report’s central warning is that a clean smart-contract audit may not cover the infrastructure that actually moves funds.

The second half of ack3’s findings, which includes Ethereum-based protocols and adjacent networks, focuses on why security reviews failed to stop the losses, and the answer is mostly scope. The dataset shows that audited projects lost $681 million through attack paths that were not inside the reviewed code or infrastructure, equal to 94% of their total losses. In the 20 most relevant audit reports connected to exploited projects, 17 were at least six months old when the attack occurred, meaning the reviewed version may not have matched the live system. The report argues that formal smart-contract reviews remain necessary, but they often stop at the contract boundary while production systems depend on admin keys, signing servers, bridge verifiers, domain configuration, and front-end code. Those operational layers became the decisive failure points. Step Finance, Humanity Protocol, and Resolv’s USR were all drained through compromised private keys and signing infrastructure rather than a flaw in the audited contract logic. That checklist also applies to multisig signers, validator operators, and bridge relayers, because each represents a human or machine path to privileged execution. For stablecoin users, that distinction matters because peg safety depends on custody and control as much as on monetary design; readers evaluating newer models can start with algorithmic stablecoins to understand how code-driven mechanisms differ from reserve-backed claims. The report also highlights the risk of front-end supply-chain attacks, where a legitimate website is altered to turn user interactions into wallet approvals. CoW Swap’s domain hijack and Polymarket’s June incident illustrate how users can be harmed without any on-chain contract exploit. Ack3 founder Josef Gattermayer warned that AI tools lower the cost of finding weak points across connected systems and chaining them into multi-layer attacks, so security reviews must assess the whole system. In practical terms, the dataset pushes users to ask what was reviewed, when it was reviewed, and who currently controls privileged keys, especially for any AI crypto wallet or automated custody layer.

COINOTAG’s reading of the ack3 dataset is that crypto security has moved from a code-quality problem to an operational-control problem. The largest losses came from single points of trust: one verifier, one admin-key pathway, one compromised front end. That conclusion matters now because COINOTAG aggregate market data shows a defensive posture, with the Fear and Greed Index at 27/100, Bitcoin holding 69.6% of our tracked market, and total tracked value at $1,817,069,893,163. For Ethereum and other smart-contract platforms, exploit risk can outweigh narrative-driven upside. The practical signal is simple: treat audit badges as one input, then verify scope freshness, key distribution, multisig thresholds, and incident response before depositing.

COINOTAG does not provide financial advisory services. This content is for informational purposes only and should not be considered investment advice. Cryptocurrency investments involve high risk.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
Sarah Chen

Sarah Chen

COINOTAG author

View all posts
AI-AssistedMarket Analyst·Sarah Chen is a market analyst specializing in technical analysis and risk management for cryptocurrency markets, with five years of active trading desk experience.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments