{"id":19459,"date":"2026-04-22T13:06:23","date_gmt":"2026-04-22T13:06:23","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/04\/22\/kelpdao-hacker-launders-funds-as-jefferies-warns-of-wall-street-chill\/"},"modified":"2026-04-22T13:06:23","modified_gmt":"2026-04-22T13:06:23","slug":"kelpdao-hacker-launders-funds-as-jefferies-warns-of-wall-street-chill","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/04\/22\/kelpdao-hacker-launders-funds-as-jefferies-warns-of-wall-street-chill\/","title":{"rendered":"KelpDAO hacker launders funds as Jefferies warns of Wall Street chill"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/media.crypto.news\/2025\/08\/crypto-news-bull-tokenizing-Wall-Street-option02.webp\" \/><\/p>\n<div>\n<p class=\"is-style-lead\">The attacker behind KelpDAO\u2019s nearly $300 million rsETH exploit is now laundering funds from Ethereum to Arbitrum and into Tron-based USDT.<\/p>\n<div id=\"cn-block-summary-block_cda9673c21ba432d329381ccdfda132f\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>KelpDAO\u2019s exploiter is moving roughly $300 million in stolen funds through Arbitrum and into Tron-based USDT.<\/li>\n<li>The hack could cool Wall Street\u2019s appetite for blockchain and tokenization deals.<\/li>\n<li>SlowMist flags new \u201cMacSync Stealer\u201d macOS malware draining crypto wallets, compounding security fears.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>The attacker behind the nearly $300 million KelpDAO <a href=\"https:\/\/crypto.news\/kelp-attack-spreads-risk-across-defi-293m-lost\/\">exploit<\/a> has begun laundering the haul, routing funds through Arbitrum and into Tron-based stablecoins, in a move that heightens fears over recoverability and traceability across DeFi.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"\/>\n<p>On-chain data shows the exploiter bridging rsETH-derived assets to Arbitrum, swapping into $USDT, and then pushing value into the Tron ecosystem, a pattern investigators say is designed to fracture the audit trail and exploit liquidity on multiple networks.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>Analysts warned in a note that the roughly $293 million KelpDAO breach \u201cmay force major Wall Street banks to reassess the pace\u201d of their blockchain and tokenization projects, arguing the incident exposes \u201ccritical infrastructure risks associated with cross-chain bridges and single-validator configurations.\u201d<\/p>\n<p>Andrew Moss, a digital assets analyst at Jefferies, said the exploit is likely to \u201cprompt major Wall Street banks to reconsider their blockchain initiatives,\u201d even if long-term use cases like stablecoins for cross-border payments remain intact.<a href=\"https:\/\/news.futunn.com\/en\/post\/71836208\/jefferies-the-kelp-dao-vulnerability-may-force-major-wall-street\" target=\"_blank\" rel=\"nofollow\"\/><\/p>\n<p>The April 18 exploit drained 116,500 rsETH \u2014 worth about $290 million to $293 million \u2014 from KelpDAO\u2019s bridge, in what research desks have called 2026\u2019s largest DeFi loss so far.<\/p>\n<p>LayerZero, whose infrastructure underpinned the rsETH bridge, said the incident was isolated to Kelp\u2019s 1-of-1 verifier setup and followed a compromise of RPC nodes, while KelpDAO has pushed back, arguing it implemented LayerZero\u2019s own defaults and that \u201cone forged signature was enough to make any cross-chain message look real.\u201d<\/p>\n<p>As investors pulled an estimated $15 billion from DeFi <a href=\"https:\/\/crypto.news\/kelp-dao-exploit-fallout-deepens-as-attacker-routes-175m-in-eth-via-privacy-rails\/\">following<\/a> the hack, the KelpDAO incident has amplified concerns that bridge design and validator assumptions are becoming systemic risk points for blue-chip protocols and institutional experiments alike.<\/p>\n<p>Yahoo Finance reported that North Korean-linked attackers have stolen nearly $600 million from on-chain applications in the first quarter alone, with KelpDAO\u2019s $294 million <a href=\"https:\/\/crypto.news\/kelp-dao-blames-layerzero-defaults-for-290m-rseth-bridge-disaster\/\">loss<\/a> emerging as the latest shock to already cautious institutional allocators.<a href=\"https:\/\/finance.yahoo.com\/markets\/crypto\/articles\/investors-pull-15bn-defi-latest-151526329.html\" target=\"_blank\" rel=\"nofollow\"\/><\/p>\n<p>Adding to the anxiety, blockchain security firm SlowMist issued an alert about an active macOS malware strain dubbed \u201cMacSync Stealer\u201d (v1.1.2), which it described as \u201chigh-risk\u201d information-stealing malware targeting crypto users.<\/p>\n<p>According to SlowMist, MacSync Stealer is capable of exfiltrating cryptocurrency wallets, browser-saved credentials, system keychains, and infrastructure keys such as SSH, AWS, and Kubernetes, often using fake AppleScript pop-ups to trick users into entering their passwords.<\/p>\n<p>SlowMist urged users \u201cto avoid running macOS scripts from unverified sources and to be especially cautious of unexpected prompts for system passwords,\u201d noting that indicators of compromise have already been shared with partners.<\/p>\n<p>With three of the day\u2019s top headlines tied to <a href=\"https:\/\/crypto.news\/north-korea-targets-blockchain-engineers-with-new-macos-malware\/\">macOS<\/a> malware or DeFi bridge exploits, and Jefferies warning that marquee hacks like KelpDAO\u2019s could \u201ctemporarily slow TradFi tokenization adoption as firms reassess security risks,\u201d the gap between crypto\u2019s technical attack surface and Wall Street\u2019s risk tolerance is suddenly front and center.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/kelpdao-hacker-launders-funds-from-ethereum-to-arbitrum-and-into-tron-based-usdt\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The attacker behind KelpDAO\u2019s nearly $300 million rsETH exploit is now laundering funds from Ethereum to Arbitrum and into Tron-based USDT. Summary KelpDAO\u2019s exploiter is moving roughly $300 million in stolen funds through Arbitrum and into Tron-based USDT. The hack could cool Wall Street\u2019s appetite for blockchain and tokenization deals. SlowMist flags new \u201cMacSync Stealer\u201d [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":19460,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-19459","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/19459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=19459"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/19459\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/19460"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=19459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=19459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=19459"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=19459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}