Kelp DAO suffers $292 million exploit linked to North Korea's Lazarus Group

Here's what it means for you.
If you’re involved in decentralized finance (DeFi), this exploit could reshape your risk assessment and investment strategies.
Why it matters
This incident highlights vulnerabilities in cross-chain infrastructure, potentially shaking investor confidence in DeFi protocols.
What happened (in 30 seconds)
- On April 18, 2026, Kelp DAO suffered a $292 million exploit, draining 116,500 rsETH tokens.
- Attackers compromised LayerZero RPC nodes, launching a DDoS attack that forced a failover to tainted verifiers.
- DeFi outflows exceeded $10 billion, with Aave facing significant potential losses and Arbitrum freezing $71 million in stolen funds.
The context you actually need
- Kelp DAO operates a liquid restaking protocol that issues rsETH, a token backed by staked Ethereum, utilizing LayerZero's cross-chain capabilities.
- LayerZero employs Delegated Verifier Networks (DVNs) for message validation, but many protocols, including Kelp, often default to a single-verifier setup, which is more susceptible to attacks.
- The Lazarus Group, a North Korean cybercrime unit, has a history of targeting DeFi bridges and RPC infrastructure, using tactics like RPC poisoning and DDoS attacks.
What's really happening
On April 18, 2026, Kelp DAO's cross-chain bridge was exploited, resulting in a staggering loss of $292 million. The attackers compromised two LayerZero RPC nodes, injecting them with fraudulent data. This was coupled with a DDoS attack on clean nodes, effectively forcing a failover to compromised verifiers. This manipulation allowed the attackers to mint 116,500 unbacked rsETH tokens, which were then funneled into Aave, triggering a cascade of liquidations and over $10 billion in DeFi withdrawals.
Kelp DAO acted swiftly, pausing contracts within 46 minutes of the exploit, which prevented an additional loss of approximately $200 million. However, the damage was already done. LayerZero issued a postmortem report attributing the attack to the Lazarus Group's TraderTraitor unit, while Kelp DAO countered that they had adhered to LayerZero's documentation and guidance.
The aftermath saw Arbitrum's Security Council freezing $71 million in stolen funds, but the attackers managed to launder $80 million. This incident has sparked a heated debate about decentralization and security within the DeFi space, as Kelp and LayerZero engaged in public disputes over accountability. Security firms like TRM Labs and Chainalysis are expected to analyze the breach further, but the immediate impact on DeFi protocols has been significant.
Despite the chaos, Ethereum prices remained stable, indicating that the broader market may not have been as affected as initially feared. However, the DeFi security markets are reflecting heightened risk pricing, suggesting that investors are becoming more cautious. The exploit has raised questions about the robustness of cross-chain infrastructure and the need for improved security measures, particularly for protocols relying on single-verifier configurations.
Who feels it first (and how)
- DeFi investors: Increased risk perception may lead to reduced investments and liquidity in DeFi protocols.
- Kelp DAO users: Those holding rsETH or using Kelp's services may face losses and reduced trust in the platform.
- LayerZero users: Protocols relying on LayerZero's infrastructure may reconsider their security setups and risk exposure.
- Aave liquidity providers: Potential losses could lead to reduced liquidity and higher borrowing costs.
- Regulators: Increased scrutiny on DeFi protocols may lead to tighter regulations in the future.
What to watch next
- Security audits: Watch for increased demand for comprehensive security audits across DeFi protocols, as investors seek assurance against similar exploits.
- Regulatory responses: Monitor any regulatory actions or guidelines that may emerge in response to this incident, particularly regarding cross-chain infrastructure.
- Market recovery: Observe how quickly DeFi protocols recover from this incident and whether investor confidence returns to pre-exploit levels.
The exploit resulted in a loss of $292 million and significant DeFi outflows.
Increased scrutiny and demand for security improvements in DeFi protocols will follow.
The long-term impact on investor confidence in DeFi and cross-chain technologies remains uncertain.
Frequently Asked Questions
- Why it matters?
- This incident highlights vulnerabilities in cross-chain infrastructure, potentially shaking investor confidence in DeFi protocols.
- What happened (in 30 seconds)?
- On April 18, 2026, Kelp DAO suffered a $292 million exploit, draining 116,500 rsETH tokens. Attackers compromised LayerZero RPC nodes, launching a DDoS attack that forced a failover to tainted verifiers. DeFi outflows exceeded $10 billion, with Aave facing significant potential losses and Arbitrum freezing $71 million in stolen funds.
- What's really happening?
- On April 18, 2026, Kelp DAO's cross-chain bridge was exploited, resulting in a staggering loss of $292 million. The attackers compromised two LayerZero RPC nodes, injecting them with fraudulent data. This was coupled with a DDoS attack on clean nodes, effectively forcing a failover to compromised verifiers. This manipulation allowed the attackers to mint 116,500 unbacked rsETH tokens, which were then funneled into Aave, triggering a cascade of liquidations and over $10 billion in DeFi withdrawal
- Who feels it first (and how)?
- DeFi investors: Increased risk perception may lead to reduced investments and liquidity in DeFi protocols. Kelp DAO users: Those holding rsETH or using Kelp's services may face losses and reduced trust in the platform. LayerZero users: Protocols relying on LayerZero's infrastructure may reconsider their security setups and risk exposure. Aave liquidity providers: Potential losses could lead to reduced liquidity and higher borrowing costs. Regulators: Increased scrutiny on DeFi protocols
- What to watch next?
- Security audits: Watch for increased demand for comprehensive security audits across DeFi protocols, as investors seek assurance against similar exploits. Regulatory responses: Monitor any regulatory actions or guidelines that may emerge in response to this incident, particularly regarding cross-chain infrastructure. Market recovery: Observe how quickly DeFi protocols recover from this incident and whether investor confidence returns to pre-exploit levels.
Covers Bitcoin plus altcoin news, market updates, and educational resources.
"Bitcoin.com provides news, market data, and guides focused on Bitcoin and the wider crypto industry."
— A47 Editor
Certik Analyst: KelpDAO Exploit Reveals High-Stakes Shift in Cross-Chain Cybercrime
A significant exploit involving KelpDAO has resulted in losses exceeding $292 million, primarily affecting its rsETH bridge and leading to the suspension of related markets by Aave. The breach is attributed to vulnerabilities in LayerZero's infrastru...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
Kelp DAO Hacker Just Moved $175 Million In Ethereum And Started Laundering It – Here Is What We Know
A significant exploit occurred at Kelp DAO, where an attacker drained approximately $292 million from its LayerZero-powered bridge, leading to Arbitrum's Security Council freezing $71 million in stolen funds. The hacker has since moved $175 million i...
Bitcoin news, technical analysis, and forecasts across crypto markets.
"NewsBTC covers Bitcoin news, technical analysis, and forecasts across crypto markets and major blockchain projects."
— A47 Editor
Crypto Community Slams LayerZero: More Verifiers Won’t Stop The Next $290M Hack
LayerZero is under fire following a significant $290 million exploit of the KelpDAO platform, attributed to a single-verifier setup that failed to meet security recommendations. The attack, linked to North Korea's Lazarus Group, has raised alarms abo...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
KelpDAO exploit exposes $290M in unbacked assets, AAVE freezes rsETH markets
The KelpDAO exploit has exposed approximately $290 million in unbacked assets, leading to AAVE freezing its rsETH markets. This incident highlights significant vulnerabilities within decentralized finance (DeFi) platforms, raising alarms about their ...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Kelp DAO blames $292M rsETH exploit on LayerZero breach, Lazarus Group involved
Kelp DAO has reported a significant exploit resulting in a loss of approximately $292 million from its rsETH bridge, attributing the breach to vulnerabilities in LayerZero's infrastructure and involvement from the North Korean Lazarus Group.
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
$280M KelpDAO exploit raises DeFi security concerns, impacts Solana markets
The KelpDAO exploit has resulted in a significant loss of approximately $280 million, raising serious concerns about the security vulnerabilities within decentralized finance (DeFi) infrastructure and its potential impact on investor confidence and m...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
LayerZero says North Korean Lazarus Group behind $292M Kelp DAO attack
LayerZero has reported that the North Korean Lazarus Group is behind the recent $292 million exploit of Kelp DAO, which involved a breach of its LayerZero-powered bridge. This incident has raised significant concerns regarding the security vulnerabil...
News and analysis on Bitcoin, altcoins, and blockchain innovation.
"Bitcoinist delivers news and analysis on Bitcoin, altcoins, and blockchain innovation with a focus on market trends and industry updates."
— A47 Editor
LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit
LayerZero has addressed the recent $290 million exploit of KelpDAO, detailing how the incident unfolded and asserting that it was not a failure of their protocol. The exploit, which drained significant funds from KelpDAO's LayerZero-powered bridge, h...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
KelpDAO bridge hack drains $292M in largest DeFi exploit of 2026
The KelpDAO bridge hack has resulted in a staggering loss of $292 million, marking it as the largest exploit in decentralized finance (DeFi) for 2026. This incident has raised alarms about the security vulnerabilities inherent in interconnected crypt...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
The $292 million Kelp exploit: how it happened, and what it means for DeFi
The Kelp exploit has resulted in a staggering loss of approximately $293 million, marking a significant breach in the decentralized finance (DeFi) sector. This incident has raised alarms about the vulnerabilities inherent in interconnected DeFi platf...