Kelp DAO (LayerZero $292M Exploit)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
On April 18, 2026, an attacker drained 116,500 rsETH (approximately $292 million) from Kelp DAO's LayerZero-powered cross-chain bridge, the largest single DeFi exploit reported in 2026. LayerZero and Chainalysis attributed the attack with preliminary confidence to North Korea's Lazarus Group, which allegedly compromised internal RPC nodes feeding a single-verifier (1-of-1) LayerZero DVN while DDoS-ing external nodes to force reliance on the compromised infrastructure. Responsibility for the vulnerable 1-of-1 configuration was initially disputed: LayerZero first blamed Kelp for a risky configuration choice, then reversed course in May 2026, publicly admitting it had allowed its DVN to operate in a 1-of-1 mode for high-value transactions.
Connected Entities
1 entitiesTimeline(6 events)
18 April 2026
Attacker drains 116,500 rsETH (~$292 million) from Kelp DAO's LayerZero-powered cross-chain bridge via a compromised single-verifier (1-of-1) DVN configuration.
CoinDesk / The BlockApril 2026
Kelp DAO's emergency pauser multisig freezes core contracts roughly 46 minutes after the initial drain, blocking two further attempted thefts.
The BlockApril 2026
LayerZero publishes an initial post-mortem characterizing the 1-of-1 DVN configuration as a Kelp configuration choice that contradicted LayerZero's recommended multi-verifier model; lending protocols including Aave, SparkLend, Fluid and Lido's earnETH freeze or pause rsETH-related markets.
Unchained / CoinDeskApril 2026
LayerZero publishes a fuller post-mortem attributing the attack, with 'preliminary confidence,' to North Korea's Lazarus Group (TraderTraitor sub-unit); Arbitrum Security Council freezes approximately 30,766 ETH of the attacker's funds.
Unchained; Chainalysis5 May 2026
Kelp DAO publishes a memo, 'Setting the Record Straight Around the LayerZero Bridge Hack,' alleging LayerZero had approved the default 1-of-1 setup; LayerZero issues a same-day statement disputing this, saying Kelp deployed multiDVN and then manually downgraded to 1/1.
CoinDeskMay 2026
LayerZero reverses its public position, apologizing and admitting: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions,' and announces it will prohibit 1-of-1 DVN configurations and require stronger default verification thresholds.
CoinDeskmodel: claude-code-investigator
generated: 9/12/2026, 11:12:04 PM
last updated: 9/12/2026, 11:12:03 PM
avoid.net — verified advice for a post-truth world