{"investigation":{"slug":"kelp-dao-layerzero-292m-exploit","entity_name":"Kelp DAO (LayerZero $292M Exploit)","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.85,"status":"draft","content_type":"investigation","summary":"On April 18, 2026, an attacker drained 116,500 rsETH (approximately $292 million) from Kelp DAO's LayerZero-powered cross-chain bridge, the largest single DeFi exploit reported in 2026. LayerZero and Chainalysis attributed the attack with preliminary confidence to North Korea's Lazarus Group, which allegedly compromised internal RPC nodes feeding a single-verifier (1-of-1) LayerZero DVN while DDoS-ing external nodes to force reliance on the compromised infrastructure. Responsibility for the vulnerable 1-of-1 configuration was initially disputed: LayerZero first blamed Kelp for a risky configuration choice, then reversed course in May 2026, publicly admitting it had allowed its DVN to operate in a 1-of-1 mode for high-value transactions.","sections":[{"content":"On Saturday, April 18, 2026 at approximately 17:35 UTC, an attacker drained 116,500 rsETH — roughly $292 million and about 18% of rsETH's circulating supply of approximately 630,000 tokens — from Kelp DAO's LayerZero Omnichain Fungible Token (OFT) bridge. The attacker called the lzReceive function on LayerZero's EndpointV2 contract to trigger release of tokens to an attacker-controlled address, effectively tricking the cross-chain messaging layer into believing a valid instruction had arrived from another network. Because the drained bridge held the rsETH reserves backing wrapped versions of the token on more than 20 other blockchains (including Base, Arbitrum, Linea, Blast, Mantle, and Scroll), the theft raised immediate concerns about the backing of rsETH across those networks. Kelp's emergency pauser multisig froze core contracts approximately 46 minutes after the initial drain (around 18:21 UTC), blocking two further attempted drains — reported as roughly 40,000 rsETH (~$100 million) or, per Chainalysis, ~$95 million — at 18:26 and 18:28 UTC. Had those follow-up attempts succeeded, total losses could have reached roughly $390 million.","heading":"The Exploit","sources":[{"url":"https://www.theblock.co/post/397988/kelp-daos-rseth-bridge-apparently-exploited-for-roughly-292-million-in-layerzero-based-attack","name":"The Block — Kelp DAO's rsETH bridge apparently exploited for roughly $292 million","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains","name":"CoinDesk — 2026's biggest crypto exploit: Kelp DAO hit for $292 million with wrapped ether stranded across 20 chains","type":"news_article","credibility":2},{"url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","name":"Chainalysis — Inside the KelpDAO Bridge Exploit","type":"research","credibility":1}],"severity":"critical"},{"content":"According to Chainalysis's post-mortem and LayerZero's own published account, the exploit did not target a smart contract vulnerability but rather LayerZero's off-chain verification infrastructure. rsETH's bridge relied on a single Decentralized Verifier Network (DVN) — LayerZero Labs' own DVN — with no secondary or independent verifier, a '1-of-1' configuration that created a single point of failure. Attackers allegedly obtained the list of RPC nodes the DVN queried, gained access to two internal LayerZero-operated RPC nodes running on separate clusters, and swapped out the software running on them so the compromised nodes reported false transaction/burn data to the DVN while continuing to return accurate data to other observers, masking the compromise. A simultaneous distributed denial-of-service (DDoS) attack against external RPC nodes the DVN also depended on allegedly forced a failover that left the DVN relying solely on the two compromised internal nodes, which fed it phantom token-burn data used to authorize the fraudulent release of rsETH on other chains.","heading":"Attack Mechanics: RPC Compromise and Single-Verifier Configuration","sources":[{"url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","name":"Chainalysis — Inside the KelpDAO Bridge Exploit","type":"research","credibility":1},{"url":"https://unchainedcrypto.com/layerzero-links-292-million-kelp-dao-bridge-exploit-to-north-koreas-lazarus-group/","name":"Unchained — LayerZero Links $292 Million Kelp DAO Bridge Exploit to North Korea's Lazarus Group","type":"news_article","credibility":2}],"severity":"critical"},{"content":"LayerZero published a post-mortem on April 20, 2026 attributing the attack 'with preliminary confidence' to North Korea's Lazarus Group, specifically its TraderTraitor sub-unit; this attribution should be treated as alleged rather than judicially established, consistent with the preliminary-confidence language LayerZero itself used. Chainalysis's public post-mortem independently examined the on-chain attack mechanics and corroborated the described technique, and blockchain researcher ZachXBT noted the attacker's wallet was funded via Tornado Cash's 1 ETH pool approximately 10 hours before the exploit, a mixing technique commonly associated with North Korea-linked actors in other DeFi thefts. On April 20, 2026, the Arbitrum Security Council froze approximately 30,766 ETH of the attacker's funds on that network.","heading":"Attribution to Lazarus Group","sources":[{"url":"https://unchainedcrypto.com/layerzero-links-292-million-kelp-dao-bridge-exploit-to-north-koreas-lazarus-group/","name":"Unchained — LayerZero Links $292 Million Kelp DAO Bridge Exploit to North Korea's Lazarus Group","type":"news_article","credibility":2},{"url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","name":"Chainalysis — Inside the KelpDAO Bridge Exploit","type":"research","credibility":1},{"url":"https://cryptonews.com/news/layerzero-lazarus-kelp-dao-exploit/","name":"cryptonews.com — LayerZero Says Lazarus Group Likely Behind Kelp DAO Exploit","type":"news_article","credibility":2}],"severity":"high"},{"content":"Responsibility for the vulnerable single-verifier configuration became a public dispute between the two parties. LayerZero's initial April 19-20, 2026 post-mortem characterized the 1-of-1 DVN setup as a configuration choice by Kelp that 'directly contradicts' LayerZero's recommended multi-DVN model, implying Kelp had disregarded guidance to use multiple independent verifiers. On May 5, 2026, Kelp published a memo titled 'Setting the Record Straight Around the LayerZero Bridge Hack,' disputing that characterization and alleging that a LayerZero team member had approved or was aware of the 1-of-1 default in a Telegram exchange, quoting an alleged message stating 'No problem on using defaults either — just tagging [redacted] here since he mentioned you may have wanted to use a custom DVN setup for verifying messages, but will leave that to your team!' LayerZero responded the same day (May 5, 2026, around 22:22 UTC) disputing Kelp's framing, stating that Kelp 'deployed multiDVN and then manually downgraded to a 1/1' configuration. On May 9, 2026, LayerZero reversed its public position, publishing a blog post opening with 'an overdue apology' and stating: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions' and 'We didn't police what our DVN was securing, which created a risk we simply didn't see.' Given the conflicting accounts and the absence of an independent third-party arbiter's finding, exact allocation of fault between Kelp's configuration choice and LayerZero's failure to police or restrict risky DVN configurations remains a matter of alleged, disputed claims rather than settled fact — though LayerZero's own admission indicates it accepted a substantial share of responsibility for allowing the configuration to exist for high-value bridges.","heading":"Disputed Responsibility: Kelp DAO vs. LayerZero","sources":[{"url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack","name":"CoinDesk — Kelp says LayerZero approved setup it blamed for $292 million bridge hack","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit","name":"CoinDesk — LayerZero says it 'made a mistake' in $292 Million Kelp exploit","type":"news_article","credibility":2},{"url":"https://finance.yahoo.com/markets/crypto/articles/kelp-blames-layerzero-292-million-223156936.html","name":"Yahoo Finance — Kelp Blames LayerZero for $292 Million Hack, Plans Switch to Chainlink","type":"news_article","credibility":2}],"severity":"high"},{"content":"Because Kelp's bridge backed rsETH deployments across 20+ chains, the exploit created solvency concerns beyond Kelp itself. Major lending protocols froze rsETH-related markets to limit exposure to potential bad debt: Aave froze rsETH markets on its V3 and V4 deployments, SparkLend and Fluid froze their rsETH markets, and Lido Finance paused deposits into its earnETH product. AAVE's token price fell approximately 10% as markets priced in potential bad debt exposure tied to rsETH collateral. Reporting also indicated the attacker used stolen rsETH as collateral for loans on lending platforms to convert stolen assets into other cryptocurrency, leaving lenders exposed to bad debt backed by stolen collateral.","heading":"Contagion Across DeFi Lending Markets","sources":[{"url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains","name":"CoinDesk — 2026's biggest crypto exploit: Kelp DAO hit for $292 million with wrapped ether stranded across 20 chains","type":"news_article","credibility":2},{"url":"https://crypto.news/layerzero-details-292m-kelpdao-exploit-and-tightens-bridge-security/","name":"crypto.news — LayerZero details $292M KelpDAO exploit and tightens bridge security","type":"news_article","credibility":2}],"severity":"high"},{"content":"Following its May 9, 2026 admission of fault, LayerZero announced remedial changes to its DVN service, including prohibiting its own DVN from servicing 1-of-1 configurations, migrating default configurations toward 5-of-5 verification where feasible, and requiring at least 3-of-3 verification on chains where only three DVNs are available. The reputational and commercial fallout was significant: Kelp DAO announced it would migrate its rsETH bridge from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP), and Solv Protocol reportedly moved more than $700 million in tokenized bitcoin infrastructure away from LayerZero. These client losses indicate the incident materially damaged confidence in LayerZero's infrastructure among major DeFi protocols, independent of how blame was ultimately apportioned.","heading":"Remediation and Aftermath","sources":[{"url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit","name":"CoinDesk — LayerZero says it 'made a mistake' in $292 Million Kelp exploit","type":"news_article","credibility":2},{"url":"https://crypto.news/layerzero-details-292m-kelpdao-exploit-and-tightens-bridge-security/","name":"crypto.news — LayerZero details $292M KelpDAO exploit and tightens bridge security","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2026-04-18","event":"Attacker drains 116,500 rsETH (~$292 million) from Kelp DAO's LayerZero-powered cross-chain bridge via a compromised single-verifier (1-of-1) DVN configuration.","source":"CoinDesk / The Block","source_url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains","date_evidence":"The attack occurred on Saturday, April 18, 2026, at 17:35 UTC."},{"date":"2026-04","event":"Kelp DAO's emergency pauser multisig freezes core contracts roughly 46 minutes after the initial drain, blocking two further attempted thefts.","source":"The Block","source_url":"https://www.theblock.co/post/397988/kelp-daos-rseth-bridge-apparently-exploited-for-roughly-292-million-in-layerzero-based-attack","date_original":"2026-04-18"},{"date":"2026-04","event":"LayerZero publishes an initial post-mortem characterizing the 1-of-1 DVN configuration as a Kelp configuration choice that contradicted LayerZero's recommended multi-verifier model; lending protocols including Aave, SparkLend, Fluid and Lido's earnETH freeze or pause rsETH-related markets.","source":"Unchained / CoinDesk","source_url":"https://unchainedcrypto.com/layerzero-links-292-million-kelp-dao-bridge-exploit-to-north-koreas-lazarus-group/","date_original":"2026-04-19"},{"date":"2026-04","event":"LayerZero publishes a fuller post-mortem attributing the attack, with 'preliminary confidence,' to North Korea's Lazarus Group (TraderTraitor sub-unit); Arbitrum Security Council freezes approximately 30,766 ETH of the attacker's funds.","source":"Unchained; Chainalysis","source_url":"https://unchainedcrypto.com/layerzero-links-292-million-kelp-dao-bridge-exploit-to-north-koreas-lazarus-group/","date_original":"2026-04-20"},{"date":"2026-05-05","event":"Kelp DAO publishes a memo, 'Setting the Record Straight Around the LayerZero Bridge Hack,' alleging LayerZero had approved the default 1-of-1 setup; LayerZero issues a same-day statement disputing this, saying Kelp deployed multiDVN and then manually downgraded to 1/1.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack","date_evidence":"LayerZero provides statement disputing Kelp's characterization (May 5, 2026, 22:22 UTC statement)."},{"date":"2026-05","event":"LayerZero reverses its public position, apologizing and admitting: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions,' and announces it will prohibit 1-of-1 DVN configurations and require stronger default verification thresholds.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit","date_original":"2026-05-09"}],"sources_used":[{"url":"https://www.theblock.co/post/397988/kelp-daos-rseth-bridge-apparently-exploited-for-roughly-292-million-in-layerzero-based-attack","name":"The Block — Kelp DAO's rsETH bridge apparently exploited for roughly $292 million","type":"news_article","archive_url":"http://web.archive.org/web/20260609050044/https://www.theblock.co/post/397988/kelp-daos-rseth-bridge-apparently-exploited-for-roughly-292-million-in-layerzero-based-attack","credibility":2,"archive_timestamp":"2026-06-09T05:00:44+00:00"},{"url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains","name":"CoinDesk — 2026's biggest crypto exploit: Kelp DAO hit for $292 million with wrapped ether stranded across 20 chains","type":"news_article","archive_url":"http://web.archive.org/web/20260804014915/https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains","credibility":2,"archive_timestamp":"2026-08-04T01:49:15+00:00"},{"url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack","name":"CoinDesk — Kelp says LayerZero approved setup it blamed for $292 million bridge hack","type":"news_article","archive_url":"http://web.archive.org/web/20260801083712/https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack","credibility":2,"archive_timestamp":"2026-08-01T08:37:12+00:00"},{"url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit","name":"CoinDesk — LayerZero says it 'made a mistake' in $292 Million Kelp exploit","type":"news_article","archive_url":"http://web.archive.org/web/20260724213636/https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit","credibility":2,"archive_timestamp":"2026-07-24T21:36:36+00:00"},{"url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","name":"Chainalysis — Inside the KelpDAO Bridge Exploit","type":"research","archive_url":"http://web.archive.org/web/20260730015225/https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","credibility":1,"archive_timestamp":"2026-07-30T01:52:25+00:00"},{"url":"https://unchainedcrypto.com/layerzero-links-292-million-kelp-dao-bridge-exploit-to-north-koreas-lazarus-group/","name":"Unchained — LayerZero Links $292 Million Kelp DAO Bridge Exploit to North Korea's Lazarus Group","type":"news_article","archive_url":"http://web.archive.org/web/20260902154419/https://unchainedcrypto.com/layerzero-links-292-million-kelp-dao-bridge-exploit-to-north-koreas-lazarus-group/","credibility":2,"archive_timestamp":"2026-09-02T15:44:19+00:00"},{"url":"https://cryptonews.com/news/layerzero-lazarus-kelp-dao-exploit/","name":"cryptonews.com — LayerZero Says Lazarus Group Likely Behind Kelp DAO Exploit","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://crypto.news/layerzero-details-292m-kelpdao-exploit-and-tightens-bridge-security/","name":"crypto.news — LayerZero details $292M KelpDAO exploit and tightens bridge security","type":"news_article","archive_url":"http://web.archive.org/web/20260724175454/https://crypto.news/layerzero-details-292m-kelpdao-exploit-and-tightens-bridge-security/","credibility":2,"archive_timestamp":"2026-07-24T17:54:54+00:00"},{"url":"https://finance.yahoo.com/markets/crypto/articles/kelp-blames-layerzero-292-million-223156936.html","name":"Yahoo Finance — Kelp Blames LayerZero for $292 Million Hack, Plans Switch to Chainlink","type":"news_article","archive_url":"http://web.archive.org/web/20260827191908/https://finance.yahoo.com/markets/crypto/articles/kelp-blames-layerzero-292-million-223156936.html","credibility":2,"archive_timestamp":"2026-08-27T19:19:08+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-09-12T23:12:04.070926+00:00","updated_at":"2026-09-13T01:11:41.250234+00:00"}}