Kelp DAO's rsETH Bridge Exploit Results in $292 Million Loss Attributed to Lazarus Group

Here's what it means for you.
If you're involved in decentralized finance (DeFi), this incident highlights the risks associated with cross-chain bridges and single-verifier configurations.
Why it matters
This exploit underscores vulnerabilities in DeFi infrastructure, potentially shaking investor confidence and leading to stricter regulations.
What happened (in 30 seconds)
- On April 18, 2026, Kelp DAO's rsETH bridge was exploited, draining 116,500 rsETH valued at approximately $292 million.
- LayerZero Labs attributed the attack to North Korea's Lazarus Group, citing RPC node poisoning and DDoS attacks.
- Kelp DAO paused affected contracts within 46 minutes but disputes LayerZero's blame, pointing to infrastructure issues.
The context you actually need
- Kelp DAO operates rsETH, a liquid restaking token that allows multi-asset restaking on Ethereum, increasing its liquidity across chains.
- LayerZero provides cross-chain interoperability through its Decentralized Verifier Network (DVN), where a 1-of-1 verifier setup creates a single point of failure.
- Lazarus Group, known for sophisticated crypto thefts, has a history of targeting bridges and infrastructure to fund North Korea's regime activities.
What's really happening
On April 18, 2026, Kelp DAO's rsETH cross-chain bridge fell victim to a sophisticated exploit that drained 116,500 rsETH, valued at approximately $292 million. The attackers compromised two LayerZero RPC nodes, feeding falsified data to the DVN verifier while simultaneously launching DDoS attacks on backup nodes. This forced Kelp DAO to rely on tainted nodes, which approved a forged cross-chain message that minted unbacked rsETH.
Kelp DAO detected the exploit and paused affected contracts within 46 minutes, effectively blocking further attempts to drain funds. However, the damage was already done, leading to a significant decline in total value locked (TVL) across DeFi platforms, with Aave freezing markets and assessing potential bad debt from the attacker's leveraged positions.
LayerZero issued a post-mortem on April 20, attributing the attack to Lazarus Group's TraderTraitor unit and criticizing Kelp's single-verifier setup. Kelp DAO responded the same day, asserting that the 1-of-1 DVN configuration was LayerZero's documented default, which they had been using since January 2024. They argued that the breach targeted LayerZero's infrastructure rather than their own setup.
This incident has triggered a chain reaction within the DeFi ecosystem. Aave saw over $1.5 billion in USDC withdrawn, and the total value locked in DeFi fell by $13 billion in just two days. The exploit has heightened scrutiny on single-verifier bridges, with LayerZero vowing to halt message signing for 1/1 DVN applications. Kelp DAO has blacklisted the attacker's wallets and is evaluating the resumption of services.
The exploit not only raises questions about the security of cross-chain bridges but also highlights the broader implications for investor confidence in DeFi. As the ecosystem continues to evolve, the need for robust security measures and diversified verification methods becomes increasingly critical.
Who feels it first (and how)
- DeFi investors: Facing potential losses and increased scrutiny on investments.
- Kelp DAO users: Directly impacted by the exploit and potential loss of funds.
- Aave users: Affected by market freezes and liquidity issues.
- LayerZero clients: Facing heightened concerns over security and infrastructure reliability.
- Regulators: Likely to increase scrutiny on DeFi protocols and their security measures.
What to watch next
- Regulatory responses: Watch for potential regulations targeting DeFi protocols, especially those using single-verifier setups. This could reshape the landscape of decentralized finance.
- Security audits: Increased demand for comprehensive security audits in DeFi projects may emerge, influencing investment decisions and project viability.
- Market recovery: Monitor how quickly the DeFi market can recover from this incident, particularly in terms of total value locked and investor confidence.
The exploit resulted in a loss of $292 million in rsETH.
Increased scrutiny on single-verifier bridges and potential regulatory actions in the DeFi space.
The long-term impact on investor confidence and the future of cross-chain interoperability.
Frequently Asked Questions
- Why it matters?
- This exploit underscores vulnerabilities in DeFi infrastructure, potentially shaking investor confidence and leading to stricter regulations.
- What happened (in 30 seconds)?
- On April 18, 2026, Kelp DAO's rsETH bridge was exploited, draining 116,500 rsETH valued at approximately $292 million. LayerZero Labs attributed the attack to North Korea's Lazarus Group, citing RPC node poisoning and DDoS attacks. Kelp DAO paused affected contracts within 46 minutes but disputes LayerZero's blame, pointing to infrastructure issues.
- What's really happening?
- On April 18, 2026, Kelp DAO's rsETH cross-chain bridge fell victim to a sophisticated exploit that drained 116,500 rsETH, valued at approximately $292 million. The attackers compromised two LayerZero RPC nodes, feeding falsified data to the DVN verifier while simultaneously launching DDoS attacks on backup nodes. This forced Kelp DAO to rely on tainted nodes, which approved a forged cross-chain message that minted unbacked rsETH. Kelp DAO detected the exploit and paused affected contracts with
- Who feels it first (and how)?
- DeFi investors: Facing potential losses and increased scrutiny on investments. Kelp DAO users: Directly impacted by the exploit and potential loss of funds. Aave users: Affected by market freezes and liquidity issues. LayerZero clients: Facing heightened concerns over security and infrastructure reliability. Regulators: Likely to increase scrutiny on DeFi protocols and their security measures.
- What to watch next?
- Regulatory responses: Watch for potential regulations targeting DeFi protocols, especially those using single-verifier setups. This could reshape the landscape of decentralized finance. Security audits: Increased demand for comprehensive security audits in DeFi projects may emerge, influencing investment decisions and project viability. Market recovery: Monitor how quickly the DeFi market can recover from this incident, particularly in terms of total value locked and investor confidence.
Covers Bitcoin plus altcoin news, market updates, and educational resources.
"Bitcoin.com provides news, market data, and guides focused on Bitcoin and the wider crypto industry."
— A47 Editor
Certik Analyst: KelpDAO Exploit Reveals High-Stakes Shift in Cross-Chain Cybercrime
A significant exploit involving KelpDAO has resulted in losses exceeding $292 million, primarily affecting its rsETH bridge and leading to the suspension of related markets by Aave. The breach is attributed to vulnerabilities in LayerZero's infrastru...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
Kelp DAO Hacker Just Moved $175 Million In Ethereum And Started Laundering It – Here Is What We Know
A significant exploit occurred at Kelp DAO, where an attacker drained approximately $292 million from its LayerZero-powered bridge, leading to Arbitrum's Security Council freezing $71 million in stolen funds. The hacker has since moved $175 million i...
Bitcoin news, technical analysis, and forecasts across crypto markets.
"NewsBTC covers Bitcoin news, technical analysis, and forecasts across crypto markets and major blockchain projects."
— A47 Editor
Crypto Community Slams LayerZero: More Verifiers Won’t Stop The Next $290M Hack
LayerZero is under fire following a significant $290 million exploit of the KelpDAO platform, attributed to a single-verifier setup that failed to meet security recommendations. The attack, linked to North Korea's Lazarus Group, has raised alarms abo...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
KelpDAO exploit exposes $290M in unbacked assets, AAVE freezes rsETH markets
The KelpDAO exploit has exposed approximately $290 million in unbacked assets, leading to AAVE freezing its rsETH markets. This incident highlights significant vulnerabilities within decentralized finance (DeFi) platforms, raising alarms about their ...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Kelp DAO blames $292M rsETH exploit on LayerZero breach, Lazarus Group involved
Kelp DAO has reported a significant exploit resulting in a loss of approximately $292 million from its rsETH bridge, attributing the breach to vulnerabilities in LayerZero's infrastructure and involvement from the North Korean Lazarus Group.
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
$280M KelpDAO exploit raises DeFi security concerns, impacts Solana markets
The KelpDAO exploit has resulted in a significant loss of approximately $280 million, raising serious concerns about the security vulnerabilities within decentralized finance (DeFi) infrastructure and its potential impact on investor confidence and m...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
LayerZero says North Korean Lazarus Group behind $292M Kelp DAO attack
LayerZero has reported that the North Korean Lazarus Group is behind the recent $292 million exploit of Kelp DAO, which involved a breach of its LayerZero-powered bridge. This incident has raised significant concerns regarding the security vulnerabil...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit
LayerZero has addressed the recent $290 million exploit of KelpDAO, detailing how the incident unfolded and asserting that it was not a failure of their protocol. The exploit, which drained significant funds from KelpDAO's LayerZero-powered bridge, h...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
KelpDAO bridge hack drains $292M in largest DeFi exploit of 2026
The KelpDAO bridge hack has resulted in a staggering loss of $292 million, marking it as the largest exploit in decentralized finance (DeFi) for 2026. This incident has raised alarms about the security vulnerabilities inherent in interconnected crypt...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
The $292 million Kelp exploit: how it happened, and what it means for DeFi
The Kelp exploit has resulted in a staggering loss of approximately $293 million, marking a significant breach in the decentralized finance (DeFi) sector. This incident has raised alarms about the vulnerabilities inherent in interconnected DeFi platf...