Skip to main content
Sign in

KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus

avoid.net/kelpdao-layerzero-bridge-exploit-april-2026-dprk-lazarus2/100·91% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

On April 18, 2026, attackers preliminarily attributed to North Korea's Lazarus Group (TraderTraitor subunit) drained approximately $292 million in rsETH from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest single DeFi exploit of 2026 and accounting for a significant share of all H1 2026 crypto hack losses. The attack exploited a 1-of-1 Decentralized Verifier Node (DVN) configuration by compromising internal RPC nodes and DDoS-ing external nodes, forcing the bridge to accept a phantom burn message and release 116,500 rsETH to attacker-controlled addresses. A public dispute over responsibility followed, with LayerZero initially blaming KelpDAO's configuration before later partially acknowledging its own failure to police high-value transaction security; the exploit created an estimated $124–$230 million in bad debt on Aave and triggered a coordinated DeFi industry recovery effort called DeFi United.

Have evidence about KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus?

Timeline(14 events)

2023-01-01

Wu Huihui, a Chinese crypto broker later linked to laundering KelpDAO exploit proceeds, is indicted for laundering Lazarus Group crypto thefts. Funding chains from the KelpDAO exploit were later traced to a Bitcoin wallet he controlled as far back as 2018.

TRM Labs

2026-03-06

Alleged start of the social engineering campaign: attackers harvest session keys from a LayerZero Labs developer, enabling access to LayerZero's RPC cloud environment and planting of poisoned internal RPC nodes in preparation for the exploit.

Web search aggregation of reporting

2026-04-01

Drift Protocol hack: alleged North Korean hackers (identified as a distinct group from TraderTraitor) steal $285 million from Drift via compromised multisig signers and exploitation of Solana durable nonce features — the first of two large DPRK attacks in April 2026.

TRM Labs

2026-04-18

At 17:35 UTC, attackers drain 116,500 rsETH (~$292 million) from KelpDAO's LayerZero OFT bridge by compromising internal RPC nodes and DDoS-ing external nodes to force the 1-of-1 DVN to accept a phantom burn message. rsETH is deployed across more than 20 networks.

CoinDesk

2026-04-18

At 18:21 UTC, KelpDAO's emergency pauser multisig freezes protocol core contracts. Two follow-up attack attempts at 18:26 and 18:28 UTC (each targeting approximately $100 million) revert. KelpDAO publicly acknowledges the exploit on social media at 20:10 UTC.

CoinDesk

2026-04-19

LayerZero publishes its initial postmortem, attributing the hack with preliminary confidence to North Korea's Lazarus Group / TraderTraitor subunit and placing responsibility on KelpDAO's 1-of-1 DVN configuration.

CoinDesk

2026-04-20

Arbitrum Security Council freezes 30,766 ETH (~$71 million) linked to the exploiter on Arbitrum One, moving funds to an intermediary wallet accessible only through further governance action. The freeze is coordinated with law enforcement.

CoinDesk

2026-04-21

Exploiter begins moving approximately 75,701 ETH (~$175 million) into freshly created Ethereum mainnet addresses and begins routing funds through THORChain, converting ETH to Bitcoin. THORChain volume surges approximately 18x.

Unchained Crypto / CryptoTimes

2026-04-23

Aave rallies DeFi partners to form DeFi United, a coordinated recovery coalition targeting full restoration of rsETH's backing.

CoinDesk

2026-04-27

DeFi United coalition pledges exceed $300 million. Major contributors include Mantle (30,000 ETH), Aave DAO (25,000 ETH), Stani Kulechov personally (5,000 ETH), Ether.fi, Lido, and Kelp DAO.

CoinDesk

2026-05-01

U.S. District Court for the Southern District of New York issues a temporary restraining order freezing the same 30,766 ETH held by Arbitrum governance, following a legal claim by North Korea terrorism judgment creditors (Han Kim and Yong Seok Kim) under the Foreign Sovereign Immunities Act and Terrorism Risk Insurance Act.

Unchained Crypto

2026-05-05

KelpDAO publishes 'Setting the Record Straight Around the LayerZero Bridge Hack,' citing Telegram screenshots to argue LayerZero personnel reviewed and approved the 1-of-1 DVN setup over 2.5 years and eight integration discussions.

CoinDesk

2026-05-10

LayerZero publishes an updated statement admitting: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions' and 'We own that,' reversing its earlier position that responsibility lay solely with KelpDAO.

CryptoTimes

2026-05-20

LayerZero publishes detailed technical breakdown of the single-verifier flaw behind the exploit and confirms migration of all OApp defaults to a minimum 3/3 DVN configuration, with a target of 5/5.

CryptoTimes
Provenance & Audit Trail
30 Wayback Archives

Decision Log

  • #1publish⛓ pending7/29/2026, 12:06:16 PM
    hash: 77vhe71SUc1VvMnkXpYzswRqMw9eDkPTJd7GM7dUkDoP

30 of 31 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 7/29/2026, 12:05:57 PM

last updated: 7/29/2026, 8:29:07 PM

avoid.net — verified advice for a post-truth world