LayerZero Labs has released its incident report on the KelpDAO bridge attack, saying about $292 million in rsETH was stolen after attackers poisoned RPC infrastructureLayerZero Labs has released its incident report on the KelpDAO bridge attack, saying about $292 million in rsETH was stolen after attackers poisoned RPC infrastructure

LayerZero details $292M KelpDAO exploit and tightens bridge security

2026/05/20 21:34
Okuma süresi: 4 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

LayerZero Labs has released its incident report on the KelpDAO bridge attack, saying about $292 million in rsETH was stolen after attackers poisoned RPC infrastructure used by its verification network and forcing policy changes around single-signer configurations.

Summary
  • LayerZero said KelpDAO was exploited for about $290 million, or roughly 116,500 rsETH, in an attack isolated to rsETH’s single-DVN setup.
  • The company said preliminary indicators point to North Korea-linked TraderTraitor and described the exploit as an infrastructure compromise rather than a protocol flaw.
  • LayerZero said it will stop signing messages for applications using 1/1 DVN configurations and is pushing affected integrators toward multi-DVN redundancy.

LayerZero Labs has published a detailed account of the KelpDAO exploit, confirming that attackers stole roughly 116,500 rsETH, worth about $292 million, by compromising downstream infrastructure tied to the verification layer used in KelpDAO’s cross-chain configuration.

The company said the incident was limited to KelpDAO’s rsETH setup because the application relied on a 1-of-1 DVN configuration with LayerZero Labs as the sole verifier, a design LayerZero said directly contradicted its standing recommendation that applications use diversified multi-DVN setups with redundancy.

In its statement, LayerZero said there was “zero contagion to any other cross-chain assets or applications,” arguing that the protocol’s modular security architecture contained the blast radius even as a single application-level configuration failed.

How the attack worked

According to LayerZero’s report, the April 18, 2026 attack targeted the RPC infrastructure relied on by the LayerZero Labs DVN rather than exploiting the LayerZero protocol, key management, or the DVN software itself.

The company said the attackers gained access to the list of RPCs used by the DVN, compromised two nodes running on separate clusters, replaced binaries on op-geth nodes, and then used malicious payloads to feed forged transaction data to the verifier while returning truthful data to other endpoints, including internal monitoring services.

To complete the exploit, the attackers also launched DDoS attacks on uncompromised RPC endpoints, which triggered failover toward the poisoned nodes and allowed the LayerZero Labs DVN to confirm transactions that had never actually occurred.

Outside forensic work broadly matches that description. Chainalysis said the attackers linked to North Korea’s Lazarus Group, specifically TraderTraitor, did not exploit a smart contract bug but instead forged a cross-chain message by poisoning internal RPC nodes and overwhelming external ones in a single-point-of-failure verification setup.

Security changes

LayerZero said the immediate response included deprecating and replacing all affected RPC nodes, restoring the LayerZero Labs DVN to operation and contacting law enforcement agencies while working with industry partners and Seal911 to trace the stolen funds.

More importantly, the company is changing how it handles risky configurations. In the statement, LayerZero said its DVN “will not sign or attest messages from any applications that utilize a 1/1 configuration,” a direct policy shift aimed at preventing a repeat of the KelpDAO failure mode.

The company is also reaching out to projects still using 1/1 configurations to migrate them to multi-DVN models with redundancy, effectively admitting that configuration flexibility without enforced safety rails was too permissive in practice.

The attribution picture has also hardened. Chainalysis linked the exploit to North Korea’s Lazarus Group and specifically TraderTraitor, while Nexus Mutual said the forged message drained $292 million from KelpDAO’s bridge in under 46 minutes, making it one of 2026’s biggest DeFi losses.

The result is a familiar but brutal lesson for cross-chain infrastructure: the smart contracts can survive intact and the protocol can still fail in practice if the off-chain trust layer is weak enough. LayerZero is now trying to prove that the right takeaway from a $292 million bridge theft is not that modular security failed, but that letting anyone run a single-signer setup was the real mistake.

SPACEX(PRE) Launchpad Is Live

SPACEX(PRE) Launchpad Is LiveSPACEX(PRE) Launchpad Is Live

Start with $100 to share 6,000 SPACEX(PRE)

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Philippine Supreme Court junks bid to block transfer of senator to ICC

Philippine Supreme Court junks bid to block transfer of senator to ICC

THE PHILIPPINE Supreme Court on Wednesday rejected a bid by Senator Ronald “Bato” M. dela Rosa to stop his arrest and transfer to the International Criminal Court
Paylaş
Bworldonline2026/05/20 21:03
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Paylaş
BitcoinEthereumNews2025/09/18 00:41
HashKey Capital Invests $20M in Crypto Derivatives Platform SignalPlus

HashKey Capital Invests $20M in Crypto Derivatives Platform SignalPlus

BitcoinWorld HashKey Capital Invests $20M in Crypto Derivatives Platform SignalPlus Asian digital asset firm HashKey has announced a $20 million strategic investment
Paylaş
Bitcoin World2026/05/20 22:00

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!