Kelp DAO Exploited for $292 Million by Lazarus Group via LayerZero Compromise

Here's what it means for you.
If you’re involved in DeFi, this incident highlights the critical importance of security configurations in cross-chain protocols.
Why it matters
This exploit underscores vulnerabilities in cross-chain mechanisms, potentially shaking investor confidence in decentralized finance.
What happened (in 30 seconds)
- On April 18, 2026, Kelp DAO's rsETH bridge was exploited for $292 million due to a compromise of LayerZero RPC nodes.
- Attackers, linked to North Korea's Lazarus Group, executed a DDoS attack to facilitate a forged message that drained 116,500 rsETH.
- Kelp DAO paused contracts within 46 minutes, preventing further losses estimated at $200 million.
The context you actually need
- Kelp DAO, based in Bengaluru, India, provides liquid restaking tokens (LRTs) like rsETH, which are backed by staked ETH and enable yield generation across DeFi.
- LayerZero's V2 OFT standard was used for cross-chain transfers, relying on Decentralized Verifier Networks (DVNs) for message validation, which were compromised.
- The Lazarus Group has a history of executing DeFi hacks to fund operations, including a recent $285 million exploit on Drift Protocol.
What's really happening
On April 18, 2026, a sophisticated attack on Kelp DAO's rsETH bridge revealed significant vulnerabilities in cross-chain protocols. The attackers, linked to North Korea's Lazarus Group, pre-funded their wallets using Tornado Cash just hours before the exploit. Between 10:20 a.m. and 11:40 a.m. PT, they compromised two LayerZero RPC nodes using selective malware and executed a DDoS attack on backup nodes to force a failover. This manipulation allowed them to validate a forged cross-chain message from Unichain, which resulted in the unauthorized release of 116,500 rsETH, valued at $292 million, from Ethereum reserves.
Kelp DAO's rapid response, pausing contracts at 18:21 UTC, prevented two additional drains that could have cost approximately $200 million. However, the damage was already done. The attackers quickly swapped the stolen rsETH for around 74,000 ETH on Aave, further complicating recovery efforts. LayerZero issued a post-mortem report attributing the exploit to the use of a single-verifier (1/1 DVN) configuration, which was debated as a default versus a recommendation. This configuration exposed the bridge to vulnerabilities that were exploited by the attackers.
The aftermath saw a significant decline in DeFi's total value locked (TVL), dropping by $13 billion within 48 hours. Aave, in particular, faced substantial losses, with estimates of bad debt ranging from $124 million to $230 million due to loans taken against the stolen rsETH. In response, the Arbitrum Security Council froze 30,766 ETH (approximately $71 million) linked to the exploiters, while Kelp DAO engaged in mitigation discussions with LayerZero and Aave, including blacklisting wallets associated with the attack.
This incident raises critical questions about the security of cross-chain protocols and the responsibilities of infrastructure providers like LayerZero. As the DeFi ecosystem continues to evolve, the implications of this exploit could lead to stricter security audits and a reevaluation of default configurations across various platforms.
Who feels it first (and how)
- DeFi Investors: Those holding rsETH or involved in liquidity pools on Aave face immediate financial risks and potential losses.
- Developers and Protocols: Teams working on cross-chain solutions may need to reassess security measures and configurations to prevent similar exploits.
- Regulatory Bodies: Increased scrutiny on DeFi protocols could lead to more stringent regulations and compliance requirements.
What to watch next
- Security Audits: Watch for announcements regarding enhanced security audits across DeFi protocols, as projects may seek to restore investor confidence.
- LayerZero's Response: Monitor how LayerZero addresses the vulnerabilities and whether they implement changes to their DVN configurations.
- Market Recovery: Observe the recovery of DeFi TVL and investor sentiment in the wake of this exploit, as it may indicate broader market stability or ongoing concerns.
The exploit resulted in a theft of $292 million from Kelp DAO's rsETH bridge.
Increased scrutiny and security measures will be implemented across DeFi protocols in response to this incident.
The long-term impact on investor confidence in cross-chain solutions and DeFi as a whole remains uncertain.
Frequently Asked Questions
- Why it matters?
- This exploit underscores vulnerabilities in cross-chain mechanisms, potentially shaking investor confidence in decentralized finance.
- What happened (in 30 seconds)?
- On April 18, 2026, Kelp DAO's rsETH bridge was exploited for $292 million due to a compromise of LayerZero RPC nodes. Attackers, linked to North Korea's Lazarus Group, executed a DDoS attack to facilitate a forged message that drained 116,500 rsETH. Kelp DAO paused contracts within 46 minutes, preventing further losses estimated at $200 million.
- What's really happening?
- On April 18, 2026, a sophisticated attack on Kelp DAO's rsETH bridge revealed significant vulnerabilities in cross-chain protocols. The attackers, linked to North Korea's Lazarus Group, pre-funded their wallets using Tornado Cash just hours before the exploit. Between 10:20 a.m. and 11:40 a.m. PT, they compromised two LayerZero RPC nodes using selective malware and executed a DDoS attack on backup nodes to force a failover. This manipulation allowed them to validate a forged cross-chain message
- Who feels it first (and how)?
- DeFi Investors: Those holding rsETH or involved in liquidity pools on Aave face immediate financial risks and potential losses. Developers and Protocols: Teams working on cross-chain solutions may need to reassess security measures and configurations to prevent similar exploits. Regulatory Bodies: Increased scrutiny on DeFi protocols could lead to more stringent regulations and compliance requirements.
- What to watch next?
- Security Audits: Watch for announcements regarding enhanced security audits across DeFi protocols, as projects may seek to restore investor confidence. LayerZero's Response: Monitor how LayerZero addresses the vulnerabilities and whether they implement changes to their DVN configurations. Market Recovery: Observe the recovery of DeFi TVL and investor sentiment in the wake of this exploit, as it may indicate broader market stability or ongoing concerns.
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
Crypto's massive exploit may force big banks to rethink their blockchain plans, Jefferies warns
The Kelp DAO suffered a significant exploit, resulting in approximately $293 million being drained from its reserves due to vulnerabilities in its LayerZero-powered bridge. This incident has raised alarms regarding the security of decentralized finan...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Kelp DAO blames $292M rsETH exploit on LayerZero breach, Lazarus Group involved
Kelp DAO has reported a significant exploit resulting in a loss of approximately $292 million from its rsETH bridge, attributing the breach to vulnerabilities in LayerZero's infrastructure and involvement from the North Korean Lazarus Group.
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
$280M KelpDAO exploit raises DeFi security concerns, impacts Solana markets
The KelpDAO exploit has resulted in a significant loss of approximately $280 million, raising serious concerns about the security vulnerabilities within decentralized finance (DeFi) infrastructure and its potential impact on investor confidence and m...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
What The Kelp DAO’s $292 Million Hack Means For XRP Holders Earning Yield
A significant security breach occurred at Kelp DAO over the weekend, where an attacker exploited the LayerZero-powered bridge, resulting in the loss of approximately $292 million in tokens. This incident marks one of the largest hacks in decentralize...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
KelpDAO bridge hack drains $292M in largest DeFi exploit of 2026
The KelpDAO bridge hack has resulted in a staggering loss of $292 million, marking it as the largest exploit in decentralized finance (DeFi) for 2026. This incident has raised alarms about the security vulnerabilities inherent in interconnected crypt...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Kelp exploit highlights problem with non-isolated DeFi lending: Crypto execs
The Kelp restaking platform has experienced a significant security breach, resulting in a loss of approximately $293 million due to an exploit involving rsETH. This incident has raised alarms within the decentralized finance (DeFi) sector, highlighti...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
Kelp DAO Suffers $292 Million rsETH Exploit – Details
Kelp DAO has experienced a significant security breach, with approximately $292 million drained from its reserves due to an exploit involving 116,500 rsETH. This incident raises serious concerns about the security of the protocol, especially followin...