Funds stolen from Kelp DAO are being laundered across multiple chains, with the majority routed through THORChain. blockchain analytics show the attacker moved roughly 75,700 ETH into Bitcoin via the cross-chain protocol, generating about $910,000 in fees for THORChain in the process.
The activity began earlier this week as the attacker split the proceeds into newly created wallets, cycling assets through THORChain and the privacy tool Umbra. Arkham data indicates the attacker’s primary wallet is now largely emptied, signaling a move to exit positions rather than hold the proceeds.
Movement through THORChain has complicated tracing and raised the odds that recoveries will be unlikely. In parallel, Arbitrum’s Security Council has frozen 30,766 ETH tied to the exploit and transferred it to an intermediary wallet, where access is limited to governance approval. The network said the intervention was carried out without disrupting operations and, in line with law-enforcement input, aimed to safeguard the ecosystem’s integrity.
Key takeaways
- The majority of looted ETH has been routed through THORChain, hindering traceability and potential recovery.
- Arbitrum froze 30,766 ETH linked to the Kelp DAO breach and moved the funds to an intermediary wallet accessed only via governance approval.
- Containment efforts limited further drain: Kelp DAO paused contracts and blacklisted attacker-linked wallets, preventing an additional 40,000 rsETH (roughly $95 million) from being drained.
- Earlier in the breach, about 116,500 restaked ETH drained from Kelp DAO’s LayerZero-based bridge, with some assets used on Aave as collateral to borrow rsETH.
- Preliminary findings point to weaknesses in the bridge’s security design, though Kelp DAO has contested some assessments and emphasized adherence to documentation and prior approvals.
What drove the move
Analysts describe the flow as an explicit exit strategy rather than an attempt to hold or re-sell the stolen assets. The funds were reorganized into multiple wallets and channeled through cross-chain rails, notably THORChain, which converts assets and generates fees for the protocol. The use of a privacy layer like Umbra further complicates tracing, as it obscures on-chain movement and makes rapid recovery more challenging.
Additionally, approximately 116,500 restaked ETH drained from Kelp DAO’s LayerZero-based bridge earlier in the week points to a broad attack surface across cross-chain infrastructure. The attacker’s subsequent use of rsETH on Aave suggests a multi-platform approach to leveraging the stolen collateral, increasing complexity for investigators and potential creditors.
Market reaction
The breach has heightened scrutiny of cross-chain bridges and DeFi risk management, though there has not been a singular, obvious price imprint in the broader crypto markets reported in the immediate aftermath. The speed and opacity of asset movement through THORChain and other services underline how quickly a breach can shift risk perceptions for investors relying on cross-chain liquidity and interoperable protocols.
Industry observers say the incident reinforces a broader trend: attackers favor exit strategies that minimize traceability, often routing funds through multiple layers to complicate enforcement and recovery efforts. The need for stronger bridge security, more transparent governance controls, and faster, coordinated incident responses weighs on market sentiment as participants reassess risk across DeFi infrastructures.
What analysts are saying
The broader DeFi community notes that the efforts to contain the breach appear to have limited further damage. Stani Kulechov, founder of Aave, described the priority as maintaining user safety and steering toward an orderly return to normal market conditions and the best possible outcome for all involved, in a post on X.
Kelp DAO’s team said work is underway toward a suitable resolution while focusing on safeguarding users and strengthening the protocol. LayerZero’s preliminary findings have drawn attention to compromised RPC nodes and the role of cross-chain verification, though Kelp DAO contends that the security setup followed default documentation and had been previously deemed appropriate.
ArkhamData and other researchers have highlighted the attacker’s exit-oriented behavior, noting that the primary wallet appears largely emptied. Arbitrum’s governance-backed freeze demonstrates a willingness to intervene in real time to prevent further damage, even as investigations continue.
Bigger picture
The episode highlights ongoing vulnerabilities in cross-chain architecture and DeFi liquidity networks. As bridges and interoperability layers grow in importance for capital efficiency, so too do security models, monitoring capabilities, and governance processes. Analysts expect continued attention on bridge security standards, incident-response playbooks, and potential updates to how cross-chain messages are validated and audited.
Law-enforcement involvement underscores the evolving regulatory dimension of on-chain crimes, with authorities increasingly engaged in tracing, freezing, and recovering assets where possible. The Kelp DAO breach adds to a string of incidents that are shaping investor expectations about risk management and the resilience of decentralized finance ecosystems amid a rapidly expanding threat landscape.
As investigations persist, key watch items include asset recovery prospects, the fate of the intermediary wallet controlled by governance, and any policy or protocol changes that could deter future exploits or improve traceability of cross-chain transactions.
What to watch next: updates on asset recovery outcomes, governance actions around the intermediary wallet, any formal security patches or framework changes from THORChain, Arbitrum, LayerZero, and related ecosystems, and forthcoming public statements from involved teams about timelines for restoring normal operation and user protections.







