KelpDAO says LayerZero’s own DVN infrastructure was breached on April 18, causing over $300M in DeFi losses. Independent researchers confirmed the attack originatedKelpDAO says LayerZero’s own DVN infrastructure was breached on April 18, causing over $300M in DeFi losses. Independent researchers confirmed the attack originated

KelpDAO Blames LayerZero for $300M Exploit, Moves to Chainlink CCIP

2026/05/06 19:15
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
  • KelpDAO says LayerZero’s own DVN infrastructure was breached on April 18, causing over $300M in DeFi losses.
  • Independent researchers confirmed the attack originated inside LayerZero’s trust boundary, not from a Kelp configuration error.
  • KelpDAO is migrating rsETH to Chainlink CCIP, citing Chainlink’s seven-year track record securing over $30 trillion in value.

KelpDAO has publicly challenged LayerZero’s account of an April 18 exploit that caused over $300 million in losses across DeFi. 

The protocol released a detailed post citing independent security researchers, internal communications, and on-chain data. 

KelpDAO Blames LayerZero for $300M Exploit, Moves to Chainlink CCIP

KelpDAO maintains that LayerZero’s own infrastructure was breached, not a configuration error on Kelp’s part. 

The team has since announced a full migration to Chainlink’s Cross-Chain Interoperability Protocol (CCIP) for rsETH security.

LayerZero Infrastructure Breach Draws Independent Scrutiny

On April 18, 2026, attackers exploited LayerZero’s DVN infrastructure, draining over $300 million from DeFi protocols. 

KelpDAO detected two additional forged transactions totaling $100 million and paused its contracts before further damage occurred. 

LayerZero’s response, published over 34 hours later, attributed the incident to an RPC-spoofing attack. However, independent researchers from SEAL 911 and others concluded that the breach originated inside LayerZero’s own trust boundary.

One security researcher stated that the LayerZero attack was not RPC poisoning but rather an infrastructure breach within the perimeter. 

Another report noted that the sole required DVN was the Etherscan-labeled LayerZero DVN, which narrowed the likely fault domain significantly. 

SEAL 911’s assessment further confirmed that threat actors, linked to the DPRK with high confidence, fraudulently triggered an attestation from the LayerZero DVN.

Attackers compromised two RPC nodes used by LayerZero’s DVN, then executed a DDoS on remaining nodes. This forced DVN signers to validate a non-existent transaction. 

LayerZero’s own postmortem acknowledged that attackers accessed its DVN’s RPC lists and swapped node binaries, stating: “the attacker was able to gain access to the list of RPCs our DVN uses, compromise two of them…and swap out binaries running the op-geth nodes.”

Further, Dune analytics data showed that roughly 47% of LayerZero OApp contracts used a 1-1 DVN setup. Over 90% of all LayerZero messages in the prior 90 days relied on the LayerZero Labs DVN. 

This directly contradicted a December 2024 statement from LayerZero’s Bryan, who claimed no application was using a 1-1 LayerZero DVN setup at the time rsETH held approximately $200 million in TVL under that exact configuration.

KelpDAO Cites Approved Configurations and Moves to Chainlink

KelpDAO stated that its 1-1 DVN setup was explicitly approved by a LayerZero Labs team member over Telegram. 

Over 2.5 years and eight documented integration discussions, LayerZero never flagged this configuration as a security risk. The team also noted that LayerZero’s own quickstart documentation still defaults to a 1-1 setup, with no optional DVN configured.

Researchers also flagged that LayerZero’s default Gasolina AWS deployment exposed a public gateway with no IAM authentication, WAF, or IP allowlists. 

One report noted that “quorum is explicitly set to 1,” meaning backup RPCs served only as failover rather than providing multi-provider consensus. 

Another researcher observed that “RPCs are mostly public endpoints,” confirming the reference deployment did not use multiple providers to reach consensus.

The protocol has now begun migrating rsETH to Chainlink CCIP and its Cross-Chain Token standard. Chainlink’s oracle network has facilitated over $30 trillion in value over seven-plus years. 

KelpDAO noted that Chainlink remained fully operational across multiple global outages, making it a more dependable infrastructure choice going forward.

KelpDAO also raised concerns about shared administrative roles between the LayerZero Labs DVN and the Nethermind DVN. 

Ten overlapping addresses held ADMIN_ROLE on both contracts as of April 8. The team argued this overlap puts into question whether the DVNs truly operate independently. 

A full forensic report will follow once the review concludes, with securing user assets remaining the team’s immediate priority.

The post KelpDAO Blames LayerZero for $300M Exploit, Moves to Chainlink CCIP appeared first on Live Bitcoin News.

Market Opportunity
Notcoin Logo
Notcoin Price(NOT)
$0.0005311
$0.0005311$0.0005311
+9.52%
USD
Notcoin (NOT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Dovish patience with geopolitical risks – TD Securities

Dovish patience with geopolitical risks – TD Securities

The post Dovish patience with geopolitical risks – TD Securities appeared on BitcoinEthereumNews.com. TD Securities analysts characterize the Bank of Canada’s (
Share
BitcoinEthereumNews2026/04/02 21:22
Cashing In On University Patents Means Giving Up On Our Innovation Future

Cashing In On University Patents Means Giving Up On Our Innovation Future

The post Cashing In On University Patents Means Giving Up On Our Innovation Future appeared on BitcoinEthereumNews.com. “It’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress,” writes Pipes. Getty Images Washington is addicted to taxing success. Now, Commerce Secretary Howard Lutnick is floating a plan to skim half the patent earnings from inventions developed at universities with federal funding. It’s being sold as a way to shore up programs like Social Security. In reality, it’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress. Yes, taxpayer dollars support early-stage research. But the real payoff comes later—in the jobs created, cures discovered, and industries launched when universities and private industry turn those discoveries into real products. By comparison, the sums at stake in patent licensing are trivial. Universities collectively earn only about $3.6 billion annually in patent income—less than the federal government spends on Social Security in a single day. Even confiscating half would barely register against a $6 trillion federal budget. And yet the damage from such a policy would be anything but trivial. The true return on taxpayer investment isn’t in licensing checks sent to Washington, but in the downstream economic activity that federally supported research unleashes. Thanks to the bipartisan Bayh-Dole Act of 1980, universities and private industry have powerful incentives to translate early-stage discoveries into real-world products. Before Bayh-Dole, the government hoarded patents from federally funded research, and fewer than 5% were ever licensed. Once universities could own and license their own inventions, innovation exploded. The result has been one of the best returns on investment in government history. Since 1996, university research has added nearly $2 trillion to U.S. industrial output, supported 6.5 million jobs, and launched more than 19,000 startups. Those companies pay…
Share
BitcoinEthereumNews2025/09/18 03:26
Unpacking The ‘Extreme Fear’ Gripping Digital Asset Markets

Unpacking The ‘Extreme Fear’ Gripping Digital Asset Markets

The post Unpacking The ‘Extreme Fear’ Gripping Digital Asset Markets appeared on BitcoinEthereumNews.com. Crypto Fear & Greed Index Plummets To 9: Unpacking The
Share
BitcoinEthereumNews2026/04/03 09:13

Starter Gold Rush: Win $2,500!

Starter Gold Rush: Win $2,500!Starter Gold Rush: Win $2,500!

Start your first trade & capture every Alpha move