No connection

Search Results

Crypto Score 68 Bearish

LayerZero Attributes $290 Million Kelp DAO Exploit to North Korean Lazarus Group

Apr 20, 2026 05:01 UTC
rsETH, LZERO
Short term

LayerZero has shifted responsibility for a $290 million theft from Kelp DAO to the protocol's own security configuration. The attack is attributed to North Korea's Lazarus Group, which utilized a sophisticated infrastructure-level exploit.

  • Kelp DAO lost $290 million due to a 1-of-1 verifier configuration
  • Attackers compromised RPC nodes and used DDoS to force failover
  • Lazarus Group linked to both Kelp and Drift Protocol exploits
  • LayerZero confirms no contagion to other applications using multi-verifier setups
  • LayerZero will now ban 1-of-1 configurations across its protocol

LayerZero has identified a critical security failure in Kelp DAO's setup as the primary cause of a $290 million exploit. The company asserts that the liquid restaking protocol ignored explicit warnings by utilizing a single-verifier configuration, creating a vulnerability that was exploited by external actors. Preliminary investigations attribute the attack to the Lazarus Group, a North Korean state-sponsored entity, and its TraderTraitor subunit. This incident follows a similar breach of Drift Protocol on April 1, bringing the total amount drained by the group from DeFi protocols to over $575 million in less than three weeks. The attackers targeted the infrastructure layer by compromising two remote procedure call (RPC) nodes. By deploying malicious software and launching a distributed denial-of-service (DDoS) attack to force a failover, the attackers tricked the verifier into authorizing the release of 116,500 rsETH. The malicious software subsequently self-destructed to erase logs. LayerZero emphasized that the protocol functioned as intended and that no other applications were affected due to their use of multi-verifier setups. In response, LayerZero Labs announced it will no longer support 1-of-1 configurations, mandating a protocol-wide migration to more secure, redundant setups to prevent future infrastructure-level attacks.

Sign up free to read the full analysis

Create a free account to unlock full AI-curated market articles, personalized alerts, and more.

Share this article

Related Articles

Stay Ahead of the Markets

Join thousands of traders using AI-powered market intelligence. Get personalized insights, real-time alerts, and advanced analysis tools.

Home
Terminal
AI
Markets
Profile