Kelp DAO loses $292 million in LayerZero bridge exploit attributed to Lazarus
Attackers stole about 116,500 rsETH (roughly $292 million) from Kelp DAO's LayerZero bridge by poisoning the RPC nodes behind a single-verifier setup; LayerZero attributed the theft to North Korea's Lazarus Group, specifically its TraderTraitor subgroup.
- Victim
- Kelp DAO
- Loss
- $292.0M
On 18 April 2026, attackers stole about 116,500 rsETH, worth roughly $292 million, from the cross-chain bridge used by Kelp DAO, a liquid restaking protocol whose rsETH token is used across many DeFi platforms. The bridge ran on LayerZero messaging infrastructure.
How the bridge was fooled
The theft did not exploit a smart contract bug. Kelp's bridge relied on a single Decentralized Verifier Network (DVN) to confirm that tokens had been burned on the source chain before releasing them on Ethereum. The attackers compromised two internal RPC nodes used by that verifier and flooded the external nodes with a DDoS attack, forcing the verifier to rely on the poisoned nodes. Those nodes reported a token burn that never happened, and the Ethereum contract released the rsETH.
Kelp paused its contracts and blacklisted the attacker's wallet, which blocked a follow-up attempt to take another 40,000 rsETH (about $95 million) with a second forged message. The Arbitrum Security Council froze connected addresses.
Attribution and fallout
LayerZero attributed the operation to North Korea's Lazarus Group, specifically the TraderTraitor subgroup, and blamed Kelp for using a 1-of-1 verifier setup despite earlier advice to use several independent verifiers. Because the stolen rsETH was deposited as collateral on lending platforms such as Aave, the theft triggered large withdrawals and liquidity stress across DeFi. Coming weeks after the roughly $280 million Drift Protocol theft, it confirmed North Korea's continued focus on large crypto heists.
Timeline
Attackers forge a cross-chain message and drain about 116,500 rsETH (around $292 million) from Kelp DAO's LayerZero bridge; Kelp pauses contracts and blocks a second attempt to take 40,000 rsETH.
LayerZero blames Kelp's single-verifier configuration and attributes the attack to North Korea's Lazarus Group (TraderTraitor).
Sources
- chainalysis.comhttps://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/
- securityweek.comhttps://www.securityweek.com/290-million-kelp-dao-crypto-heist-blamed-on-north-korea/