Forgotten Dairies
DeFi’s Decentralization Ends Where Accountability Begins -By Fransiscus Nanga Roka
The losses by KelpDAO deserves more than finger-pointing from industry figures. The industry has to be transparent about its trust assumptions, able to test its safeguards and enforceable in terms of responsibilities.
A financial system that promises decentralised trust needs to tell us why it trusts a single verification path with hundreds of millions of dollars involved. The KelpDAO exploit brings to light the gap between decentralisation as a marketing assurance and resilience as an engineering one.
Attackers drained 116,500 rsETH ($292M) from KelpDAO’s bridge on April 18, 2026. This is an example of an off-chain infrastructure attack according to Chainalysis: compromised data sources and a denial-of-service attack coordinated the verifier to sign over a transfer backed by a token burn which never happened. The receiving contract code was run against a fake version of reality that you created.
This configuration only needed a single Decentralized Verifier Network. No need for an independent second verifier to concur. This is an important distinction: a network can share the label “decentralized” while retaining a catastrophic single point of failure for a particular deployment.
This is actually the governance question underlying all that technical wreckage: who chose the configuration, who understood its dependencies, who communicated its risks and who had the power to prevent deployment of an anomaly?
In September, the case had been litigated in Canada. KelpDAO alleged that LayerZero and CEO Bryan Pellegrino misstepped around infrastructure security and risk disclosures. Pellegrino dismissed the lawsuit as baseless and vowed to fight it in B.C. Those competing positions need to be resolved, the filing alone establishes no negligence or liability on behalf of a personal kind.
But users should not need to await litigation in order to determine where the balance of responsibility lies. Before accepting assets, infrastructure providers and application operators should communicate their respective security responsibilities. Configurability has made choices, but also makes the choice to be able to explain dangerous configurations.
Attribution requires equal discipline. While investigators have tied the operation to North Korea’s Lazarus infrastructure, cybersecurity attribution is not the same as a criminal finding of culpability by a state Party. Similarly, freezing funds from crime doesn’t equal restitution to victims. That if anything, the reported freezing of more than 30,000 ETH should not be seen as full and final settlement.
Wider risk is monetary contagion. If a bridged asset is also able to be borrowed in another place, then it can allow shockwaves of uncertainty between platforms. So security reviews need to inspect these relationships between systems and look at their external data dependencies.
Five changes are urgent.
Some of which has genuinely independent verification should be required on high interference bridges with this kind of a first. The same vulnerability might be manifested multiple times by different verifiers sharing the same infrastructure, but using different names.
Second, operators should periodically reconcile asset releases with infrastructure or bridge protocol burns (or any deposits across chains). Abnormal releases must be germa triggers for threshold limits, alerts and proportionate emergency intervention.
Third, audits must include infrastructure, access controls and configuration and incident response. The security of anything the contract trusts can not be established by a smart-contract audit.
Fourth, contracts and of course public disclosures should identify identifiable legal entities that are responsible for compliance with security obligations as well as the location of a reliable forum that can resolve disputes and will enforce recovery procedures. The term DAO should never become a synonym for an organized entity skimming process fees with users having no way to pinpoint a parent counterparty to hold accountable.
Fifth, require timely incident reporting and cross border evidence preservation, asset tracing and lawful recovery. Compensation deals need to be powered by disclosures of costs, priorities and prospects.
Moving to another provider might mitigate certain risks, but resilience would seem to depend on more than a new logo on an old name.
The losses by KelpDAO deserves more than finger-pointing from industry figures. The industry has to be transparent about its trust assumptions, able to test its safeguards and enforceable in terms of responsibilities.
Never should users find out how far decentralization could go only when their funds get lost.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia

You must be logged in to post a comment Login