Trending

    LayerZero Links $292 Million Kelp DAO Exploit to North Korean Lazarus Group

    Section editor: ·High10 articles covering this·7 news sources·Updated a month ago·World
    Share:
    LayerZero Links $292 Million Kelp DAO Exploit to North Korean Lazarus Group

    Here's what it means for you.

    If you’re involved in decentralized finance (DeFi), this exploit could impact your investments and the overall stability of the ecosystem.

    Why it matters

    This incident highlights vulnerabilities in cross-chain protocols, potentially shaking investor confidence in DeFi platforms.

    What happened (in 30 seconds)

    • Kelp DAO's rsETH bridge was exploited on April 18, 2026, resulting in a loss of $292 million attributed to North Korea's Lazarus Group.
    • LayerZero confirmed that the exploit was due to a compromised RPC infrastructure in its Decentralized Verifier Network (DVN).
    • DeFi experienced significant outflows, with $13 billion leaving the ecosystem in the aftermath, although no broader contagion was reported.

    The context you actually need

    • Lazarus Group's history includes over $2 billion in cryptocurrency thefts in 2025, indicating a sustained threat to the DeFi landscape.
    • Kelp DAO's single-DVN setup was a critical vulnerability, as experts had recommended a multi-DVN configuration to prevent such exploits.
    • The aftermath saw immediate actions, including the freezing of $71 million in exploiter funds by the Arbitrum Security Council and a decline in DeFi's total value locked (TVL).

    What's really happening

    On April 18, 2026, Kelp DAO's rsETH bridge was compromised, leading to a staggering $292 million theft. This exploit was executed by the Lazarus Group, a North Korean hacking organization known for its sophisticated cyber operations. The attack exploited a single-DVN configuration within LayerZero's cross-chain messaging system, which is designed to facilitate transactions across different blockchain networks.

    The attackers targeted two independent RPC nodes that fed into LayerZero's DVN. By replacing binaries on these nodes, they were able to spoof transaction data, making it appear legitimate to the verifier while remaining undetected by monitoring systems. This manipulation was coupled with a Distributed Denial of Service (DDoS) attack on clean nodes, forcing a failover that allowed the attackers to approve forged cross-chain messages. As a result, 116,500 rsETH was drained from Kelp DAO's bridge.

    In the immediate aftermath, Kelp DAO paused all rsETH contracts across networks to mitigate further losses. LayerZero conducted a post-mortem analysis, confirming that the exploit was isolated to Kelp's single-DVN setup. They have since mandated a migration to multi-DVN configurations to enhance security and prevent similar incidents in the future.

    The exploit triggered a significant reaction in the DeFi ecosystem, with total value locked (TVL) declining by $13 to $15 billion within 48 hours. Notably, Aave, a major DeFi lending platform, lost $8.8 billion in TVL, leading to potential losses of up to $230 million. The Arbitrum Security Council acted swiftly to freeze $71 million in ETH linked to the exploit, showcasing the urgency of addressing security vulnerabilities in the DeFi space.

    This incident has sparked a broader debate within the community regarding infrastructure security and the need for robust protocols to safeguard against such attacks. While no unique governmental interventions have been reported, law enforcement agencies are collaborating with LayerZero and Kelp DAO to trace the stolen funds.

    Who feels it first (and how)

    • DeFi investors: Immediate financial losses and reduced confidence in the security of DeFi platforms.
    • Developers and protocol teams: Increased scrutiny and pressure to enhance security measures and infrastructure.
    • Regulatory bodies: Potential for heightened regulatory oversight as incidents like this draw attention to the risks associated with decentralized finance.

    What to watch next

    • Security audits: Watch for increased frequency and rigor of security audits across DeFi protocols as teams respond to this exploit.
    • Regulatory developments: Monitor any new regulations or guidelines that may emerge in response to the exploit, particularly regarding cross-chain protocols.
    • Market recovery: Observe how quickly the DeFi ecosystem can recover its TVL and investor confidence in the wake of this incident.
    Known:

    The exploit resulted in a $292 million loss for Kelp DAO, attributed to the Lazarus Group.

    Likely:

    There will be a shift towards multi-DVN configurations in DeFi protocols to enhance security.

    Unclear:

    The long-term impact on investor confidence and the overall stability of the DeFi ecosystem remains uncertain.

    Frequently Asked Questions

    Why it matters?
    This incident highlights vulnerabilities in cross-chain protocols, potentially shaking investor confidence in DeFi platforms.
    What happened (in 30 seconds)?
    Kelp DAO's rsETH bridge was exploited on April 18, 2026, resulting in a loss of $292 million attributed to North Korea's Lazarus Group. LayerZero confirmed that the exploit was due to a compromised RPC infrastructure in its Decentralized Verifier Network (DVN). DeFi experienced significant outflows, with $13 billion leaving the ecosystem in the aftermath, although no broader contagion was reported.
    What's really happening?
    On April 18, 2026, Kelp DAO's rsETH bridge was compromised, leading to a staggering $292 million theft. This exploit was executed by the Lazarus Group, a North Korean hacking organization known for its sophisticated cyber operations. The attack exploited a single-DVN configuration within LayerZero's cross-chain messaging system, which is designed to facilitate transactions across different blockchain networks. The attackers targeted two independent RPC nodes that fed into LayerZero's DVN. By re
    Who feels it first (and how)?
    DeFi investors: Immediate financial losses and reduced confidence in the security of DeFi platforms. Developers and protocol teams: Increased scrutiny and pressure to enhance security measures and infrastructure. Regulatory bodies: Potential for heightened regulatory oversight as incidents like this draw attention to the risks associated with decentralized finance.
    What to watch next?
    Security audits: Watch for increased frequency and rigor of security audits across DeFi protocols as teams respond to this exploit. Regulatory developments: Monitor any new regulations or guidelines that may emerge in response to the exploit, particularly regarding cross-chain protocols. Market recovery: Observe how quickly the DeFi ecosystem can recover its TVL and investor confidence in the wake of this incident.
    10 Articles
    NewsBTC

    Crypto Community Slams LayerZero: More Verifiers Won’t Stop The Next $290M Hack

    LayerZero is under fire following a significant $290 million exploit of the KelpDAO platform, attributed to a single-verifier setup that failed to meet security recommendations. The attack, linked to North Korea's Lazarus Group, has raised alarms abo...

    Crypto News

    Kelp DAO blames LayerZero defaults for $290m rsETH bridge disaster

    Kelp DAO has attributed a significant security breach, resulting in a loss of approximately $290 million from its rsETH bridge, to LayerZero's default single-validator setup. This incident has sparked a blame game between Kelp DAO and LayerZero, with...

    CoinDesk

    Kelp DAO claims LayerZero’s 'default' settings are what actually caused the massive $290 million disaster

    Kelp DAO has claimed that the recent $290 million exploit of its liquid restaking protocol was caused by LayerZero's default settings, which allowed a compromised verifier to drain funds. The incident has raised significant concerns about the securit...

    Bitcoin.com

    Layerzero Claims Zero Contagion After $290M Exploit as Disputed Narratives Deepen Scrutiny

    Layerzero Labs has claimed that there is zero contagion following a significant $290 million exploit, which has raised questions about the security and reliability of its platform amidst growing scrutiny. The incident has sparked a debate regarding t...

    Crypto Briefing

    LayerZero says North Korean Lazarus Group behind $292M Kelp DAO attack

    LayerZero has reported that the North Korean Lazarus Group is behind the recent $292 million exploit of Kelp DAO, which involved a breach of its LayerZero-powered bridge. This incident has raised significant concerns regarding the security vulnerabil...

    Bitcoinist

    LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit

    LayerZero has addressed the recent $290 million exploit of KelpDAO, detailing how the incident unfolded and asserting that it was not a failure of their protocol. The exploit, which drained significant funds from KelpDAO's LayerZero-powered bridge, h...

    Techmeme

    LayerZero says North Korea's Lazarus is likely behind the $292M Kelp DAO exploit on April 18, which triggered $10B in outflows from Aave over bad debt concerns (Danny Park/The Block)

    LayerZero has identified North Korea's Lazarus group as the likely perpetrator behind the $292 million exploit of Kelp DAO's LayerZero-powered cross-chain bridge, which occurred on April 18. This incident led to Kelp pausing all rsETH contracts after...

    Crypto News

    LayerZero links Kelp DAO exploit to Lazarus as DeFi losses deepen

    LayerZero has linked the recent $292 million exploit of Kelp DAO to the Lazarus Group, attributing the breach to a single-DVN setup that compromised the security of its LayerZero-powered bridge. This incident has raised significant concerns about the...

    CoinDesk

    LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus

    LayerZero has attributed a recent $290 million exploit of the Kelp restaking platform to a setup that ignored multi-verifier recommendations, allowing attackers to compromise two RPC nodes and DDoS the rest. The incident has been linked to North Kore...

    CoinDesk

    The $292 million Kelp exploit: how it happened, and what it means for DeFi

    The Kelp exploit has resulted in a staggering loss of approximately $293 million, marking a significant breach in the decentralized finance (DeFi) sector. This incident has raised alarms about the vulnerabilities inherent in interconnected DeFi platf...