Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bitcoin quantum risk hits 1.92M BTC says Glassnode

    May 21, 2026

    Raoul Pal sees crypto hitting $100T in a decade

    May 20, 2026

    AllUnity stablecoin targets Sweden in June

    May 20, 2026
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » LayerZero details $292M KelpDAO exploit and tightens bridge security

    LayerZero details $292M KelpDAO exploit and tightens bridge security

    Isabella TaylorBy Isabella TaylorMay 20, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    LayerZero Labs has released its incident report on the KelpDAO bridge attack, saying about $292 million in rsETH was stolen after attackers poisoned RPC infrastructure used by its verification network and forcing policy changes around single-signer configurations.

    Summary

    • LayerZero said KelpDAO was exploited for about $290 million, or roughly 116,500 rsETH, in an attack isolated to rsETH’s single-DVN setup.
    • The company said preliminary indicators point to North Korea-linked TraderTraitor and described the exploit as an infrastructure compromise rather than a protocol flaw.
    • LayerZero said it will stop signing messages for applications using 1/1 DVN configurations and is pushing affected integrators toward multi-DVN redundancy.

    LayerZero Labs has published a detailed account of the KelpDAO exploit, confirming that attackers stole roughly 116,500 rsETH, worth about $292 million, by compromising downstream infrastructure tied to the verification layer used in KelpDAO’s cross-chain configuration.

    The company said the incident was limited to KelpDAO’s rsETH setup because the application relied on a 1-of-1 DVN configuration with LayerZero Labs as the sole verifier, a design LayerZero said directly contradicted its standing recommendation that applications use diversified multi-DVN setups with redundancy.

    In its statement, LayerZero said there was “zero contagion to any other cross-chain assets or applications,” arguing that the protocol’s modular security architecture contained the blast radius even as a single application-level configuration failed.

    How the attack worked

    According to LayerZero’s report, the April 18, 2026 attack targeted the RPC infrastructure relied on by the LayerZero Labs DVN rather than exploiting the LayerZero protocol, key management, or the DVN software itself.

    The company said the attackers gained access to the list of RPCs used by the DVN, compromised two nodes running on separate clusters, replaced binaries on op-geth nodes, and then used malicious payloads to feed forged transaction data to the verifier while returning truthful data to other endpoints, including internal monitoring services.

    To complete the exploit, the attackers also launched DDoS attacks on uncompromised RPC endpoints, which triggered failover toward the poisoned nodes and allowed the LayerZero Labs DVN to confirm transactions that had never actually occurred.

    Outside forensic work broadly matches that description. Chainalysis said the attackers linked to North Korea’s Lazarus Group, specifically TraderTraitor, did not exploit a smart contract bug but instead forged a cross-chain message by poisoning internal RPC nodes and overwhelming external ones in a single-point-of-failure verification setup.

    Security changes

    LayerZero said the immediate response included deprecating and replacing all affected RPC nodes, restoring the LayerZero Labs DVN to operation and contacting law enforcement agencies while working with industry partners and Seal911 to trace the stolen funds.

    More importantly, the company is changing how it handles risky configurations. In the statement, LayerZero said its DVN “will not sign or attest messages from any applications that utilize a 1/1 configuration,” a direct policy shift aimed at preventing a repeat of the KelpDAO failure mode.

    The company is also reaching out to projects still using 1/1 configurations to migrate them to multi-DVN models with redundancy, effectively admitting that configuration flexibility without enforced safety rails was too permissive in practice.

    The attribution picture has also hardened. Chainalysis linked the exploit to North Korea’s Lazarus Group and specifically TraderTraitor, while Nexus Mutual said the forged message drained $292 million from KelpDAO’s bridge in under 46 minutes, making it one of 2026’s biggest DeFi losses.

    The result is a familiar but brutal lesson for cross-chain infrastructure: the smart contracts can survive intact and the protocol can still fail in practice if the off-chain trust layer is weak enough. LayerZero is now trying to prove that the right takeaway from a $292 million bridge theft is not that modular security failed, but that letting anyone run a single-signer setup was the real mistake.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Isabella Taylor

    Related Posts

    Bitcoin quantum risk hits 1.92M BTC says Glassnode

    May 21, 2026

    Raoul Pal sees crypto hitting $100T in a decade

    May 20, 2026

    AllUnity stablecoin targets Sweden in June

    May 20, 2026

    Comments are closed.

    Don't Miss

    Bitcoin quantum risk hits 1.92M BTC says Glassnode

    Crypto May 21, 2026

    Bitcoin quantum exposure covers 1.92 million BTC, or 9.6% of total supply, Glassnode warned in…

    Raoul Pal sees crypto hitting $100T in a decade

    May 20, 2026

    AllUnity stablecoin targets Sweden in June

    May 20, 2026

    Exa Labs raises $250 million in funding led by a16z

    May 20, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    This feed has expired. Please contact us for pricing options.

    May 5, 2026

    AGII Introduces Scalable AI Execution Layer for Decentralized Systems

    May 1, 2026

    Lithosphere Deploys Full-Stack Development Environment for AI-Native Applications

    May 1, 2026

    Lithosphere Integrates AI Mock Providers for Continuous Integration Workflows

    April 30, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    ‘Updating the Plumbing of the Financial System’: BlackRock CEO Larry Fink Says Tokenization Could Expand Access to Markets

    March 24, 2026

    Tether Announces $184,000,000,000 Independent Audit With Big Four Accounting Firm

    March 25, 2026

    Coinbase Adds Little-Known Crypto Asset to Listing Roadmap for Spot Trading

    March 25, 2026

    Bitcoin quantum risk hits 1.92M BTC says Glassnode

    May 21, 2026

    Raoul Pal sees crypto hitting $100T in a decade

    May 20, 2026

    AllUnity stablecoin targets Sweden in June

    May 20, 2026
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    Demo
    Top Posts

    This feed has expired. Please contact us for pricing options.

    May 5, 20265 Views

    Lithosphere Deploys Full-Stack Development Environment for AI-Native Applications

    May 1, 20262 Views

    Lithosphere Integrates AI Mock Providers for Continuous Integration Workflows

    April 30, 20262 Views

    AGII Introduces Scalable AI Execution Layer for Decentralized Systems

    May 1, 20261 Views
    Don't Miss

    Bitcoin quantum risk hits 1.92M BTC says Glassnode

    Crypto May 21, 2026

    Bitcoin quantum exposure covers 1.92 million BTC, or 9.6% of total supply, Glassnode warned in…

    Raoul Pal sees crypto hitting $100T in a decade

    May 20, 2026

    AllUnity stablecoin targets Sweden in June

    May 20, 2026

    Exa Labs raises $250 million in funding led by a16z

    May 20, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    Pi Network launches Protocol 23 on May 11

    May 2, 202616 Views

    Xiaomi rolls out MiMo V2.5 with multimodal AI and improved efficiency

    April 23, 202615 Views

    Meta’s Muse Spark ends its open-source AI era

    May 9, 202612 Views

    Pi Network confirms Consensus 2026 sponsorship

    May 2, 202610 Views
    Don't Miss

    Bitcoin quantum risk hits 1.92M BTC says Glassnode

    Crypto May 21, 2026

    Bitcoin quantum exposure covers 1.92 million BTC, or 9.6% of total supply, Glassnode warned in…

    Raoul Pal sees crypto hitting $100T in a decade

    May 20, 2026

    AllUnity stablecoin targets Sweden in June

    May 20, 2026

    Exa Labs raises $250 million in funding led by a16z

    May 20, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Bitcoin quantum risk hits 1.92M BTC says Glassnode

    May 21, 2026

    Raoul Pal sees crypto hitting $100T in a decade

    May 20, 2026

    AllUnity stablecoin targets Sweden in June

    May 20, 2026
    Recent Posts
    • Bitcoin quantum risk hits 1.92M BTC says Glassnode
    • Raoul Pal sees crypto hitting $100T in a decade
    • AllUnity stablecoin targets Sweden in June
    • Exa Labs raises $250 million in funding led by a16z
    • CBDC ban hides US digital dollar work says Massad
    © 2026 - 2026

    Type above and press Enter to search. Press Esc to cancel.