Futures
Access hundreds of perpetual contracts
TradFi
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Pre-IPOs
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
GateRouter
Smartly choose from 40+ AI models, with 0% extra fees
KelpDAO stolen funds triggered a money laundering process, with THORChain’s daily volume surging 10x.
On-chain analysts Specter monitoring shows that on April 22, the North Korean hacker group TraderTraitor began money-laundering operations using the stolen funds from KelpDAO—only three hours after the Arbitrum Security Committee froze approximately 30,766 ETH. The attackers routed the funds via the THORChain bridge to the Bitcoin network, causing daily transactions to exceed 10 times the 30-day daily average.
Money-laundering operation details: three wallets, mixing methods, and cross-chain transfers
(Source: Arkham)
The attackers split the remaining funds across three wallets: the first held about 25k ETH (about $57.6 million), the second held about 25.7k ETH (about $59.2 million), and the third began laundering immediately after receiving the funds and currently has only about 3,800 ETH left (about $8 million).
During the laundering process, the stolen funds were mixed with the illicit proceeds from the BTC Turk (2025) and Bybit (2025) hacker incidents—this is a typical operational pattern for the TraderTraitor organization. By integrating funds from multiple incidents, it increases the difficulty of on-chain tracking. Specter noted that although it traced 356 related addresses, some intermediary wallets were not included in the statistics; the total number of addresses used throughout the process exceeds 400.
The downstream ripple effects of the KelpDAO attack: from Aave bad debt to a sharp drop in DeFi TVL
According to Messari’s analysis, the root cause of this attack lies in the LayerZero EndpointV2 1:1 DVN configuration, which allows attackers to forge cross-chain messages. After compromising two LayerZero DVN nodes, the attackers simulated the rsETH burn and triggered 116,500 unauthorized releases of rsETH.
The downstream impact spread rapidly across the entire DeFi ecosystem: estimated Aave bad debt ranges from $123.7 million to $230.1 million; TVL fell from about $45.8 billion to $35.7 billion; overall DeFi TVL declined by more than $13.0 billion within 48 hours; the AAVE token dropped by about 25%; and the WETH market reached 100% utilization, triggering a $6.2 billion outflow of funds.
Early response measures and the rsETH holder compensation plan
The main response measures include: the Arbitrum Security Committee freezing approximately 30,766 ETH; Kelp pausing all rsETH contracts on the mainnet and the L2 layer; and LayerZero prohibiting the future use of the 1:1 DVN configuration. Kelp is currently considering implementing a 16% proportional loss compensation measure for rsETH holders, but Messari pointed out that this could affect affected users’ confidence in the affected protocols and the pace of recovery.
Frequently Asked Questions
Why did TraderTraitor choose THORChain as the money-laundering channel?
THORChain is a permissionless cross-chain liquidity protocol that allows asset swaps between different blockchains without requiring KYC verification. In the earlier Bybit hacker incident, TraderTraitor also used the same THORChain channel, indicating that it has become the fixed operating pattern of the North Korean hacker group after large-scale theft.
Why did this money-laundering involve mixing funds with the Bybit and BTC Turk incidents?
Mixing funds is a standard money-laundering technique: after combining stolen funds from multiple incidents, it makes it harder for trackers to identify the original source and destination/ownership of specific funds. During the circulation of the stolen KelpDAO funds through THORChain, they were already mixed with illicit funds from the 2025 BTC Turk and Bybit hacker incidents, forming a funding trail that is even harder to unravel.
How will Kelp’s 16% proportional loss compensation plan affect rsETH holders?
If the compensation plan is ultimately confirmed, rsETH holders will bear approximately 16% of the loss according to their position size—meaning that for every 100 rsETH, the nominal value of assets will be discounted by about 16%. The compensation mechanism can help partially mitigate losses for affected users, but it may also affect how quickly the market restores confidence in rsETH and the Kelp protocol overall.