$175M Ethereum Exodus: Kelp DAO Attacker Begins Laundering Operation Through Privacy Protocols
The Kelp DAO attacker has made their first major move since draining nearly $290 million in restaked Ether—shifting approximately 75,700 ETH ($175 million) across newly created blockchain addresses in what blockchain intelligence firm Arkham identifies as a classic money laundering pattern. The

The Kelp DAO attacker has made their first major move since draining nearly $290 million in restaked Ether—shifting approximately 75,700 ETH ($175 million) across newly created blockchain addresses in what blockchain intelligence firm Arkham identifies as a classic money laundering pattern.
The Initial Transfer Pattern
On Tuesday, the attacker-controlled wallet moved the substantial Ethereum haul through three transactions, including a 25,000 ETH transfer to one address and 50,700 ETH plus 0.7 ETH to another. This represents the attacker's first significant attempt to fragment and obscure the stolen funds since Saturday's exploit.
Blockchain investigator ZachXBT flagged additional suspicious activity: the attacker has begun routing capital through privacy-focused crypto protocols. His Tuesday Telegram analysis identified three THORChain transactions totaling approximately $1.5 million, alongside a separate $78,000 transfer through Umbra—both protocols known for complicating transaction tracing.
Why These Protocols Matter for Trading Analysis
THORChain's lack of traditional Know Your Customer requirements makes it an attractive vector for crypto laundering. This pattern mirrors the $1.4 billion Bybit hack in 2025, when attackers converted 83% of stolen Ether to Bitcoin, with 72% flowing through THORChain. Even with that routing, Bybit CEO Ben Zhou noted 77% remained traceable—highlighting both the challenges and possibilities for forensic crypto analysis.
Cascading DeFi Damage Continues
The exploit's ripple effects intensified market stress across major protocols. Arbitrum's 12-member security council emergency-froze 30,766 ETH tied to the breach, placing funds into an intermediary wallet controlled solely through governance.
Aave absorbed direct damage when the attacker deployed stolen rsETH as collateral. Initial estimates suggested $195 million in exposure, but Aave's official incident report outlined more granular scenarios: either $123.7 million or $230.1 million in realized bad debt depending on liquidation dynamics.
Liquidity Crisis Signals Market Stress
The protocol's response tells us plenty about crypto market intelligence during crises. Tuesday saw Aave unfreeze Wrapped Ether (WETH) reserves on Ethereum Core V3—a modest relief that came with brutal borrowing rate spikes. USDT lending rates exploded from 3% to 14%, marking the highest level since December 2024 per CryptoQuant research head Julio Moreno.
The fear proved contagious: Aave's total value locked plummeted $10 billion to $16.4 billion as users fled for safer harbors. WETH reserves remain frozen across Ethereum Prime, Arbitrum, Base, Mantle, and Linea, signaling continued caution throughout the trading ecosystem.
What Triggered the Exploit
LayerZero's post-mortem analysis reveals the architectural flaw: Kelp DAO's 1/1 decentralized verifier network configuration created a single point of failure. The rsETH bridge relied on one verifier path for cross-chain messages—a vulnerability LayerZero previously warned against but Kelp DAO implemented anyway.
Alpha Take
The attacker's immediate pivot toward THORChain and Umbra indicates sophisticated operational security thinking, yet blockchain surveillance still captured the movements. For portfolio risk management, monitor whether these funds successfully convert to Bitcoin or stablecoins—conversion rates and exchange routing will determine recovery odds. Aave's $10 billion TVL exodus and rate spikes suggest contagion fears remain elevated; watch whether other lending protocols face similar capital flight or if stabilization holds.
Originally reported by
CoinTelegraph
Not financial advice. Crypto investing involves significant risk. Past performance does not guarantee future results. Always do your own research.