Trending

    Kelp DAO's rsETH Bridge Exploit Results in $292 Million Loss Attributed to Lazarus Group

    Section editor: ·High10 articles covering this·5 news sources·Updated a month ago·World
    Share:
    Kelp DAO's rsETH Bridge Exploit Results in $292 Million Loss Attributed to Lazarus Group

    Here's what it means for you.

    If you're involved in decentralized finance (DeFi), this incident highlights the risks associated with cross-chain bridges and single-verifier configurations.

    Why it matters

    This exploit underscores vulnerabilities in DeFi infrastructure, potentially shaking investor confidence and leading to stricter regulations.

    What happened (in 30 seconds)

    • On April 18, 2026, Kelp DAO's rsETH bridge was exploited, draining 116,500 rsETH valued at approximately $292 million.
    • LayerZero Labs attributed the attack to North Korea's Lazarus Group, citing RPC node poisoning and DDoS attacks.
    • Kelp DAO paused affected contracts within 46 minutes but disputes LayerZero's blame, pointing to infrastructure issues.

    The context you actually need

    • Kelp DAO operates rsETH, a liquid restaking token that allows multi-asset restaking on Ethereum, increasing its liquidity across chains.
    • LayerZero provides cross-chain interoperability through its Decentralized Verifier Network (DVN), where a 1-of-1 verifier setup creates a single point of failure.
    • Lazarus Group, known for sophisticated crypto thefts, has a history of targeting bridges and infrastructure to fund North Korea's regime activities.

    What's really happening

    On April 18, 2026, Kelp DAO's rsETH cross-chain bridge fell victim to a sophisticated exploit that drained 116,500 rsETH, valued at approximately $292 million. The attackers compromised two LayerZero RPC nodes, feeding falsified data to the DVN verifier while simultaneously launching DDoS attacks on backup nodes. This forced Kelp DAO to rely on tainted nodes, which approved a forged cross-chain message that minted unbacked rsETH.

    Kelp DAO detected the exploit and paused affected contracts within 46 minutes, effectively blocking further attempts to drain funds. However, the damage was already done, leading to a significant decline in total value locked (TVL) across DeFi platforms, with Aave freezing markets and assessing potential bad debt from the attacker's leveraged positions.

    LayerZero issued a post-mortem on April 20, attributing the attack to Lazarus Group's TraderTraitor unit and criticizing Kelp's single-verifier setup. Kelp DAO responded the same day, asserting that the 1-of-1 DVN configuration was LayerZero's documented default, which they had been using since January 2024. They argued that the breach targeted LayerZero's infrastructure rather than their own setup.

    This incident has triggered a chain reaction within the DeFi ecosystem. Aave saw over $1.5 billion in USDC withdrawn, and the total value locked in DeFi fell by $13 billion in just two days. The exploit has heightened scrutiny on single-verifier bridges, with LayerZero vowing to halt message signing for 1/1 DVN applications. Kelp DAO has blacklisted the attacker's wallets and is evaluating the resumption of services.

    The exploit not only raises questions about the security of cross-chain bridges but also highlights the broader implications for investor confidence in DeFi. As the ecosystem continues to evolve, the need for robust security measures and diversified verification methods becomes increasingly critical.

    Who feels it first (and how)

    • DeFi investors: Facing potential losses and increased scrutiny on investments.
    • Kelp DAO users: Directly impacted by the exploit and potential loss of funds.
    • Aave users: Affected by market freezes and liquidity issues.
    • LayerZero clients: Facing heightened concerns over security and infrastructure reliability.
    • Regulators: Likely to increase scrutiny on DeFi protocols and their security measures.

    What to watch next

    • Regulatory responses: Watch for potential regulations targeting DeFi protocols, especially those using single-verifier setups. This could reshape the landscape of decentralized finance.
    • Security audits: Increased demand for comprehensive security audits in DeFi projects may emerge, influencing investment decisions and project viability.
    • Market recovery: Monitor how quickly the DeFi market can recover from this incident, particularly in terms of total value locked and investor confidence.
    Known:

    The exploit resulted in a loss of $292 million in rsETH.

    Likely:

    Increased scrutiny on single-verifier bridges and potential regulatory actions in the DeFi space.

    Unclear:

    The long-term impact on investor confidence and the future of cross-chain interoperability.

    Frequently Asked Questions

    Why it matters?
    This exploit underscores vulnerabilities in DeFi infrastructure, potentially shaking investor confidence and leading to stricter regulations.
    What happened (in 30 seconds)?
    On April 18, 2026, Kelp DAO's rsETH bridge was exploited, draining 116,500 rsETH valued at approximately $292 million. LayerZero Labs attributed the attack to North Korea's Lazarus Group, citing RPC node poisoning and DDoS attacks. Kelp DAO paused affected contracts within 46 minutes but disputes LayerZero's blame, pointing to infrastructure issues.
    What's really happening?
    On April 18, 2026, Kelp DAO's rsETH cross-chain bridge fell victim to a sophisticated exploit that drained 116,500 rsETH, valued at approximately $292 million. The attackers compromised two LayerZero RPC nodes, feeding falsified data to the DVN verifier while simultaneously launching DDoS attacks on backup nodes. This forced Kelp DAO to rely on tainted nodes, which approved a forged cross-chain message that minted unbacked rsETH. Kelp DAO detected the exploit and paused affected contracts with
    Who feels it first (and how)?
    DeFi investors: Facing potential losses and increased scrutiny on investments. Kelp DAO users: Directly impacted by the exploit and potential loss of funds. Aave users: Affected by market freezes and liquidity issues. LayerZero clients: Facing heightened concerns over security and infrastructure reliability. Regulators: Likely to increase scrutiny on DeFi protocols and their security measures.
    What to watch next?
    Regulatory responses: Watch for potential regulations targeting DeFi protocols, especially those using single-verifier setups. This could reshape the landscape of decentralized finance. Security audits: Increased demand for comprehensive security audits in DeFi projects may emerge, influencing investment decisions and project viability. Market recovery: Monitor how quickly the DeFi market can recover from this incident, particularly in terms of total value locked and investor confidence.
    10 Articles
    Bitcoin.com

    Certik Analyst: KelpDAO Exploit Reveals High-Stakes Shift in Cross-Chain Cybercrime

    A significant exploit involving KelpDAO has resulted in losses exceeding $292 million, primarily affecting its rsETH bridge and leading to the suspension of related markets by Aave. The breach is attributed to vulnerabilities in LayerZero's infrastru...

    Bitcoinist

    Kelp DAO Hacker Just Moved $175 Million In Ethereum And Started Laundering It – Here Is What We Know

    A significant exploit occurred at Kelp DAO, where an attacker drained approximately $292 million from its LayerZero-powered bridge, leading to Arbitrum's Security Council freezing $71 million in stolen funds. The hacker has since moved $175 million i...

    NewsBTC

    Crypto Community Slams LayerZero: More Verifiers Won’t Stop The Next $290M Hack

    LayerZero is under fire following a significant $290 million exploit of the KelpDAO platform, attributed to a single-verifier setup that failed to meet security recommendations. The attack, linked to North Korea's Lazarus Group, has raised alarms abo...

    Crypto Briefing

    KelpDAO exploit exposes $290M in unbacked assets, AAVE freezes rsETH markets

    The KelpDAO exploit has exposed approximately $290 million in unbacked assets, leading to AAVE freezing its rsETH markets. This incident highlights significant vulnerabilities within decentralized finance (DeFi) platforms, raising alarms about their ...

    Crypto Briefing

    Kelp DAO blames $292M rsETH exploit on LayerZero breach, Lazarus Group involved

    Kelp DAO has reported a significant exploit resulting in a loss of approximately $292 million from its rsETH bridge, attributing the breach to vulnerabilities in LayerZero's infrastructure and involvement from the North Korean Lazarus Group.

    Crypto Briefing

    $280M KelpDAO exploit raises DeFi security concerns, impacts Solana markets

    The KelpDAO exploit has resulted in a significant loss of approximately $280 million, raising serious concerns about the security vulnerabilities within decentralized finance (DeFi) infrastructure and its potential impact on investor confidence and m...

    Crypto Briefing

    LayerZero says North Korean Lazarus Group behind $292M Kelp DAO attack

    LayerZero has reported that the North Korean Lazarus Group is behind the recent $292 million exploit of Kelp DAO, which involved a breach of its LayerZero-powered bridge. This incident has raised significant concerns regarding the security vulnerabil...

    Bitcoinist

    LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit

    LayerZero has addressed the recent $290 million exploit of KelpDAO, detailing how the incident unfolded and asserting that it was not a failure of their protocol. The exploit, which drained significant funds from KelpDAO's LayerZero-powered bridge, h...

    Crypto Briefing

    KelpDAO bridge hack drains $292M in largest DeFi exploit of 2026

    The KelpDAO bridge hack has resulted in a staggering loss of $292 million, marking it as the largest exploit in decentralized finance (DeFi) for 2026. This incident has raised alarms about the security vulnerabilities inherent in interconnected crypt...

    CoinDesk

    The $292 million Kelp exploit: how it happened, and what it means for DeFi

    The Kelp exploit has resulted in a staggering loss of approximately $293 million, marking a significant breach in the decentralized finance (DeFi) sector. This incident has raised alarms about the vulnerabilities inherent in interconnected DeFi platf...