Kelp DAO Exploiter Successfully Moves $175M in Stolen ETH Through THORchain's Cross-Chain Bridge
The attacker behind the Kelp DAO exploit has managed to launder nearly the entire haul of 75,700 stolen ETH through THORchain, Crypto Sleuth reported. This represents a masterclass in evading detection—and a stark reminder that even after a major crypto security breach, sophisticated bad actors kno

The attacker behind the Kelp DAO exploit has managed to launder nearly the entire haul of 75,700 stolen ETH through THORchain, Crypto Sleuth reported. This represents a masterclass in evading detection—and a stark reminder that even after a major crypto security breach, sophisticated bad actors know exactly how to obfuscate stolen funds.
Let's break down what happened: The wallet connected to the Kelp DAO exploit has successfully laundered most of the $175 million in stolen Ether. Here's where it gets interesting—another $71 million remains frozen by Arbitrum's security council, which essentially means that portion is currently out of play.
The Laundering Pipeline
THORchain, the decentralized cross-chain liquidity protocol, appears to be the exploiter's laundry of choice. By routing the stolen ETH through THORchain's bridge infrastructure, the attacker achieved something critical in the crypto underworld: breaking the on-chain transaction trail. THORchain's design allows for atomic swaps across blockchains without custodial intermediaries, making it ideal for someone looking to convert suspicious assets into different forms or move them across networks.
This type of exploit amplifies an ongoing tension in the crypto ecosystem. While decentralized protocols champion censorship resistance and permissionless access, these same properties make them attractive to bad actors trying to hide illicit funds. It's a feature, not a bug—but it's a feature with real consequences.
The Bigger Picture
The Kelp DAO incident highlights a critical vulnerability in DeFi security. The protocol's architecture apparently allowed an attacker to drain approximately 75,700 ETH in a single transaction, suggesting either a logic error in smart contracts or a more sophisticated vulnerability that bypassed standard security measures.
From a portfolio and trading perspective, this matters. Major exploits erode confidence in affected protocols and can trigger broader market sentiment shifts. Investors holding Kelp DAO's native token RST watched value collapse, while traders adjusted their risk assessments across similar staking derivative platforms.
The Frozen Funds Factor
The Arbitrum security council's decision to freeze $71 million in stolen funds demonstrates that layer-2 solutions do have recourse mechanisms—something that distinguishes them from fully permissionless systems. However, the fact that three-quarters of the stolen amount already moved through THORchain shows that determined attackers can outpace defensive measures.
Blockchain analysis firms are likely tracking these movements across chains, but recovery remains uncertain. This is where crypto's transparency cuts both ways: every transaction is visible on-chain, yet actually freezing or retrieving assets depends on willing cooperation from protocols and exchanges downstream.
Alpha Take
The Kelp DAO exploit demonstrates that even with cross-chain security measures and council oversight, determined attackers can execute sophisticated laundering operations through decentralized bridges. For traders and portfolio managers, this reinforces the need for due diligence on smart contract audits and protocol governance structures. The $71 million frozen represents partial mitigation, but the $175 million in successfully moved ETH suggests that security in crypto remains reactive, not preventative.
Originally reported by
CoinTelegraph
Not financial advice. Crypto investing involves significant risk. Past performance does not guarantee future results. Always do your own research.