LayerZero links KelpDAO exploit to Lazarus Group
LayerZero links the KelpDAO exploit, with losses up to $2.9B, to North Korea’s Lazarus Group. The attack exploited a single-verifier setup, prompting stricter security measures.
LayerZero Labs and multiple reports have linked the recent KelpDAO exploit—which resulted in losses estimated between $290 million and $2.9 billion—to North Korea’s Lazarus Group, specifically its TraderTraitor subgroup. The attack occurred on April 18, 2026, targeting KelpDAO’s rsETH liquid restaking token by exploiting a single-verifier (DVN) setup. This happened despite LayerZero’s prior recommendation to use a multi-verifier architecture. Attackers compromised remote procedure call (RPC) nodes by injecting fraudulent blockchain data and launched DDoS attacks to force the system to validate fake transactions. As a result, a significant portion of rsETH’s circulating supply was drained. LayerZero emphasized that its protocol was not fundamentally flawed and that applications using multiple DVNs were unaffected. The company has suspended signature and verification services for single-verifier configurations and is accelerating migration to multi-DVN setups. This incident highlights the importance of robust security practices and adherence to recommended configurations.