All articles
OpSecDeep Dive

Inside a $292M DeFi Crisis: Lessons from KPK's rsETH War Room

June 18, 2026·5 min read

On April 18, 2026, Kelp DAO's rsETH token was exploited through a LayerZero V2 bridge vulnerability. KPK had 20 minutes to decide whether their entire portfolio was at risk — a rare inside account of institutional incident response during a live DeFi crisis.

On April 18, 2026, Kelp DAO's rsETH token was exploited through a LayerZero V2 bridge vulnerability. A single compromised attestation point made a $292M malicious funds release look legitimate to the protocol. Within hours, Aave, SparkLend, Compound, and Fluid had paused rsETH markets. Lido and Upshift froze deposits.

KPK — an institutional onchain asset manager running capital across six DAO treasuries and curated Morpho vaults — had 20 minutes to decide whether their entire portfolio was at risk. Their post-mortem, published June 10, offers a rare inside account of what institutional incident response actually looks like during a live DeFi crisis.

The Timeline

rsETH Incident Response Timeline
00:00Signal received (X/Telegram)
00:00 – 00:20War room activated
00:20 – 00:33Manual exit agent
00:20 – 12:20Blast-radius assessment
00:20 – Day +14Post-mortem + 97 ships

The Five Systems That Mattered

1. Pre-Deployed Permissions Layer

KPK's non-custodial smart-contract framework defines exactly what the asset manager can and cannot do — without ever taking custody of client funds. During the crisis, no new approvals or keys were needed. The permissions were already in place from mandate deployment. The team could move funds in seconds, but only inside pre-drawn lines.

2. Automated Agents + Human Escalation

KPK runs automated agents that continuously manage allocations across approved markets — maintaining withdrawal liquidity, monitoring risk parameters, executing rebalances. When a high-confidence risk alert fires on a preconfigured incident trigger, exit agents pull liquidity before a human is even in the loop. But the rsETH vector was novel, requiring manual escalation within 13 minutes of activation. The architecture compresses the vulnerability window without eliminating human judgment.

3. Parallel Blast-Radius Mapping

Six DAOs (ENS, CoW DAO, Arbitrum, Balancer, Nexus Mutual, dYdX), each with independent mandates and risk parameters. KPK ran a cross-reference matrix in parallel: direct exposure, indirect lending-protocol contagion, shared oracles, shared bridge infrastructure, liquidation health under stress. Tailored impact summaries were published to each DAO's governance channel. All logged and timestamped.

4. Three-Stage Communication Protocol

Stage one: acknowledge immediately. Aware and responding. No detail, no speculation. Stage two: update with actions taken — deposits halted, positions exited, scope confirmed. Stage three: resolve with full account of what happened and what changed. Each stage requires legal sign-off. It prevents premature disclosure that creates panic or legal exposure, and it handles the challenge of communicating with multiple audiences simultaneously: DAO committees, public vault depositors, and the wider market.

5. Drills That Build Muscle Memory

KPK runs quarterly company-wide drills plus monthly curation drills with extra reps on high-probability scenarios. Attack classes include multisig compromises, flash loan exploits, oracle failures, liquidation cascades, and stablecoin depegs. In March 2026 — one month before the real incident — the team ran a drill simulating a RedStone oracle malfunction. They built actual transaction payloads to hot-swap affected oracles in production. Those payloads are now wired into the threat-detection platform for fully automated emergency response.

Incident Response Architecture
1Signal received
2Automated trigger? → Yes: Auto exit agent pulls liquidity
3No → War room activated (6 assigned roles)
4Permissions Layer — pre-deployed authority
5Manual exit agent (13 min)
6Blast-radius mapping — 6 DAOs in parallel
7Stage 1: Acknowledge → Stage 2: Update → Stage 3: Resolve + ship
8Post-mortem + quarterly drills

What Shipped After: 97 New Monitors

AreaChange
Detection97 new monitors covering oracle attacks, governance attacks, and bridge exploits
AutomationExtended scope of conditions triggering automatic fund movements; upstream protocol deps wired into alerting
Signal intakeAutomated X screening for trusted security accounts — not all emergencies give you 10 minutes
On-callFormal PagerDuty rotation with phone-based escalation for after-hours
Depeg monitoringLayered detection with secondary-source price comparison and per-asset historical thresholds
SpeedForced rebalances on user withdrawals — alert to onchain execution in 17 seconds
ToolingInternal Safe transaction scoping tool to prevent multisig attack vectors

The Core Discipline

KPK runs post-mortems after every incident and after every false alarm. A dismissed threat that wasn't communicated fast enough reveals a process gap. A real alert that took too long to reach the right person reveals a detection gap. Both get fixed. Hot washes within hours capture the picture while memory is fresh. Full post-mortems within 48 hours produce structural changes.

Every incident closes with a list of changes that ship.

Actionable Steps for Web3 Teams

  1. Pre-deploy your permissions layer. Your emergency authority should exist before the emergency. If your team needs a multisig vote to start responding, you've already lost.
  2. Assign six war room roles today. On-call lead, analysts, strategy, engineering, comms, legal. Write names into each role. Rotate quarterly.
  3. Run drills that produce transaction payloads. Quarterly company-wide, monthly for risk. Simulate real attack classes and build executable exits — not table reads.
  4. Audit your key personnel, not just your code. Every team member with key access should be independently opsec-audited for phishing resistance, key storage, and comms hygiene.
  5. Dual-layer detection. Automated onchain monitoring for deterministic triggers + human signal channels (X, Telegram, partner protocols) for novel vectors.
  6. Adopt three-stage comms with legal gates. Acknowledge within minutes. Update within hours. Resolve within 48 hours. Silence is read as weakness.
  7. Template your blast-radius matrix now. Build it before you need it: direct exposure, contagion risk, shared oracles, shared bridge infra, shared collateral types.
  8. Measure and compress your alert-to-execution pipeline. KPK ships forced rebalances in 17 seconds. Know your number.

Source: KPK — Inside the War Room: How KPK Responds (June 10, 2026).

Delta V Intel pipelineGenerated and verified through the Delta V intelligence system.

Explore IntelHub →

Want high-signal intel like this in your inbox?

Get in touch