KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus
Summary
On April 18, 2026, attackers preliminarily attributed to North Korea's Lazarus Group (TraderTraitor subunit) drained approximately $292 million in rsETH from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest single DeFi exploit of 2026 and accounting for a significant share of all H1 2026 crypto hack losses. The attack exploited a 1-of-1 Decentralized Verifier Node (DVN) configuration by compromising internal RPC nodes and DDoS-ing external nodes, forcing the bridge to accept a phantom burn message and release 116,500 rsETH to attacker-controlled addresses. A public dispute over responsibility followed, with LayerZero initially blaming KelpDAO's configuration before later partially acknowledging its own failure to police high-value transaction security; the exploit created an estimated $124–$230 million in bad debt on Aave and triggered a coordinated DeFi industry recovery effort called DeFi United.
Connected Entities
1 entities · 10 linked investigations- + 3 more
Timeline(14 events)
2023-01-01
Wu Huihui, a Chinese crypto broker later linked to laundering KelpDAO exploit proceeds, is indicted for laundering Lazarus Group crypto thefts. Funding chains from the KelpDAO exploit were later traced to a Bitcoin wallet he controlled as far back as 2018.
TRM Labs2026-03-06
Alleged start of the social engineering campaign: attackers harvest session keys from a LayerZero Labs developer, enabling access to LayerZero's RPC cloud environment and planting of poisoned internal RPC nodes in preparation for the exploit.
Web search aggregation of reporting2026-04-01
Drift Protocol hack: alleged North Korean hackers (identified as a distinct group from TraderTraitor) steal $285 million from Drift via compromised multisig signers and exploitation of Solana durable nonce features — the first of two large DPRK attacks in April 2026.
TRM Labs2026-04-18
At 17:35 UTC, attackers drain 116,500 rsETH (~$292 million) from KelpDAO's LayerZero OFT bridge by compromising internal RPC nodes and DDoS-ing external nodes to force the 1-of-1 DVN to accept a phantom burn message. rsETH is deployed across more than 20 networks.
CoinDesk2026-04-18
At 18:21 UTC, KelpDAO's emergency pauser multisig freezes protocol core contracts. Two follow-up attack attempts at 18:26 and 18:28 UTC (each targeting approximately $100 million) revert. KelpDAO publicly acknowledges the exploit on social media at 20:10 UTC.
CoinDesk2026-04-19
LayerZero publishes its initial postmortem, attributing the hack with preliminary confidence to North Korea's Lazarus Group / TraderTraitor subunit and placing responsibility on KelpDAO's 1-of-1 DVN configuration.
CoinDesk2026-04-20
Arbitrum Security Council freezes 30,766 ETH (~$71 million) linked to the exploiter on Arbitrum One, moving funds to an intermediary wallet accessible only through further governance action. The freeze is coordinated with law enforcement.
CoinDesk2026-04-21
Exploiter begins moving approximately 75,701 ETH (~$175 million) into freshly created Ethereum mainnet addresses and begins routing funds through THORChain, converting ETH to Bitcoin. THORChain volume surges approximately 18x.
Unchained Crypto / CryptoTimes2026-04-23
Aave rallies DeFi partners to form DeFi United, a coordinated recovery coalition targeting full restoration of rsETH's backing.
CoinDesk2026-04-27
DeFi United coalition pledges exceed $300 million. Major contributors include Mantle (30,000 ETH), Aave DAO (25,000 ETH), Stani Kulechov personally (5,000 ETH), Ether.fi, Lido, and Kelp DAO.
CoinDesk2026-05-01
U.S. District Court for the Southern District of New York issues a temporary restraining order freezing the same 30,766 ETH held by Arbitrum governance, following a legal claim by North Korea terrorism judgment creditors (Han Kim and Yong Seok Kim) under the Foreign Sovereign Immunities Act and Terrorism Risk Insurance Act.
Unchained Crypto2026-05-05
KelpDAO publishes 'Setting the Record Straight Around the LayerZero Bridge Hack,' citing Telegram screenshots to argue LayerZero personnel reviewed and approved the 1-of-1 DVN setup over 2.5 years and eight integration discussions.
CoinDesk2026-05-10
LayerZero publishes an updated statement admitting: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions' and 'We own that,' reversing its earlier position that responsibility lay solely with KelpDAO.
CryptoTimes2026-05-20
LayerZero publishes detailed technical breakdown of the single-verifier flaw behind the exploit and confirms migration of all OApp defaults to a minimum 3/3 DVN configuration, with a target of 5/5.
CryptoTimesDecision Log
- #1publish⛓ pending7/29/2026, 12:06:16 PMhash: 77vhe71SUc1VvMnkXpYzswRqMw9eDkPTJd7GM7dUkDoP
30 of 31 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 7/29/2026, 12:05:57 PM
last updated: 7/29/2026, 8:29:07 PM
avoid.net — verified advice for a post-truth world