• CONTACT
  • MARKETCAP
Coin  Deskk
  • BOOKMARKS
  • What’s New
  • Cryptocurrency
  • Pages
    • Contact Us
    • Search Page
    • Customize Interests
    • My Bookmarks
  • Home Coin
  • Home Coin
Reading: LayerZero details $292M KelpDAO exploit and tightens bridge security
Share
Coin  DeskkCoin  Deskk
Font ResizerAa
  • Home
  • Crypto
  • Market
  • Blockchain
  • Contact
Search
© 2026 Coindeskk News Network. All Rights Reserved.
What's New

LayerZero details $292M KelpDAO exploit and tightens bridge security

Crypto
Last updated: May 20, 2026 11:11 pm
Crypto
Published: May 20, 2026
Share
LayerZero details $292M KelpDAO exploit and tightens bridge security

LayerZero Labs has released its incident report on the KelpDAO bridge attack, saying about $292 million in rsETH was stolen after attackers poisoned RPC infrastructure used by its verification network and forcing policy changes around single-signer configurations. Summary LayerZero said KelpDAO was exploited for about $290 million, or roughly 116,500 rsETH, in an attack isolated to rsETH’s single-DVN setup. The company said preliminary indicators point to North Korea-linked TraderTraitor and described the exploit as an infrastructure compromise rather than a protocol flaw. LayerZero said it will stop signing messages for applications using 1/1 DVN configurations and is pushing affected integrators toward multi-DVN redundancy. LayerZero Labs has published a detailed account of the KelpDAO exploit, confirming that attackers stole roughly 116,500 rsETH, worth about $292 million, by compromising downstream infrastructure tied to the verification layer used in KelpDAO’s cross-chain configuration. The company said the incident was limited to KelpDAO’s rsETH setup because the application relied on a 1-of-1 DVN configuration with LayerZero Labs as the sole verifier, a design LayerZero said directly contradicted its standing recommendation that applications use diversified multi-DVN setups with redundancy. In its statement, LayerZero said there was “zero contagion to any other cross-chain assets or applications,” arguing that the protocol’s modular security architecture contained the blast radius even as a single application-level configuration failed. How the attack worked According to LayerZero’s report, the April 18, 2026 attack targeted the RPC infrastructure relied on by the LayerZero Labs DVN rather than exploiting the LayerZero protocol, key management, or the DVN software itself. The company said the attackers gained access to the list of RPCs used by the DVN, compromised two nodes running on separate clusters, replaced binaries on op-geth nodes, and then used malicious payloads to feed forged transaction data to the verifier while returning truthful data to other endpoints, including internal monitoring services. To complete the exploit, the attackers also launched DDoS attacks on uncompromised RPC endpoints, which triggered failover toward the poisoned nodes and allowed the LayerZero Labs DVN to confirm transactions that had never actually occurred. Outside forensic work broadly matches that description. Chainalysis said the attackers linked to North Korea’s Lazarus Group, specifically TraderTraitor, did not exploit a smart contract bug but instead forged a cross-chain message by poisoning internal RPC nodes and overwhelming external ones in a single-point-of-failure verification setup. Security changes LayerZero said the immediate response included deprecating and replacing all affected RPC nodes, restoring the LayerZero Labs DVN to operation and contacting law enforcement agencies while working with industry partners and Seal911 to trace the stolen funds. More importantly, the company is changing how it handles risky configurations. In the statement, LayerZero said its DVN “will not sign or attest messages from any applications that utilize a 1/1 configuration,” a direct policy shift aimed at preventing a repeat of the KelpDAO failure mode. The company is also reaching out to projects still using 1/1 configurations to migrate them to multi-DVN models with redundancy, effectively admitting that configuration flexibility without enforced safety rails was too permissive in practice. The attribution picture has also hardened. Chainalysis linked the exploit to North Korea’s Lazarus Group and specifically TraderTraitor, while Nexus Mutual said the forged message drained $292 million from KelpDAO’s bridge in under 46 minutes, making it one of 2026’s biggest DeFi losses. The result is a familiar but brutal lesson for cross-chain infrastructure: the smart contracts can survive intact and the protocol can still fail in practice if the off-chain trust layer is weak enough. LayerZero is now trying to prove that the right takeaway from a $292 million bridge theft is not that modular security failed, but that letting anyone run a single-signer setup was the real mistake.

WLFI’s Push Sparks Trump Crypto Surge: Inside the Market-Moving Revelation
Unlock Tezos’ Power: How Calypso Upgrade Revolutionizes L2 Etherlink Now
Prediction markets debate closes Consensus Miami
Unlock Crypto’s Hidden Gems: Discover Untapped Opportunities Now!
Unlock Solana’s Future: a16z’s $50M Bet on Jito Revolutionizes Staking

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Algorand price approaches golden cross amid Robinhood listing, will it reclaim $0.20? Algorand price approaches golden cross amid Robinhood listing, will it reclaim $0.20?
Next Article Mouro closes $400M fund as Santander backs AI and blockchain bets Mouro closes $400M fund as Santander backs AI and blockchain bets

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
Shiba Inu Plunges: Will It Survive This Critical Test?
Shiba Inu Plunges: Will It Survive This Critical Test?
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin  Deskk

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

© Coindeskk News Network. All Rights Reserved.