Skip to main content
AVOID.NET

KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus

avoid.net/kelpdao-layerzero-bridge-exploit-april-2026-dprk-lazarus0/100·91% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2vjatB…KzVu

Summary

On April 18, 2026, attackers preliminarily attributed to North Korea's Lazarus Group (TraderTraitor subunit) drained approximately $292 million in rsETH from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest single DeFi exploit of 2026 and accounting for a significant share of all H1 2026 crypto hack losses. The attack exploited a 1-of-1 Decentralized Verifier Node (DVN) configuration by compromising internal RPC nodes and DDoS-ing external nodes, forcing the bridge to accept a phantom burn message and release 116,500 rsETH to attacker-controlled addresses. A public dispute over responsibility followed, with LayerZero initially blaming KelpDAO's configuration before later partially acknowledging its own failure to police high-value transaction security; the exploit created an estimated $124–$230 million in bad debt on Aave and triggered a coordinated DeFi industry recovery effort called DeFi United.

Connected Entities

1 entities
Organizations
KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus
Relationships
  • + 3 more
Have evidence about KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus?
0
Accepted
2
Under review
0
Rejected / revoked

Community submissions

Timeline(14 events)

2023

Wu Huihui, a Chinese crypto broker later linked to laundering KelpDAO exploit proceeds, is indicted for laundering Lazarus Group crypto thefts. Funding chains from the KelpDAO exploit were later traced to a Bitcoin wallet he controlled as far back as 2018.

TRM Labs

6 March 2026

Alleged start of the social engineering campaign: attackers harvest session keys from a LayerZero Labs developer, enabling access to LayerZero's RPC cloud environment and planting of poisoned internal RPC nodes in preparation for the exploit.

Web search aggregation of reporting

April 2026

Drift Protocol hack: alleged North Korean hackers (identified as a distinct group from TraderTraitor) steal $285 million from Drift via compromised multisig signers and exploitation of Solana durable nonce features — the first of two large DPRK attacks in April 2026.

TRM Labs

18 April 2026

At 17:35 UTC, attackers drain 116,500 rsETH (~$292 million) from KelpDAO's LayerZero OFT bridge by compromising internal RPC nodes and DDoS-ing external nodes to force the 1-of-1 DVN to accept a phantom burn message. rsETH is deployed across more than 20 networks.

CoinDesk

18 April 2026

At 18:21 UTC, KelpDAO's emergency pauser multisig freezes protocol core contracts. Two follow-up attack attempts at 18:26 and 18:28 UTC (each targeting approximately $100 million) revert. KelpDAO publicly acknowledges the exploit on social media at 20:10 UTC.

CoinDesk

19 April 2026

LayerZero publishes its initial postmortem, attributing the hack with preliminary confidence to North Korea's Lazarus Group / TraderTraitor subunit and placing responsibility on KelpDAO's 1-of-1 DVN configuration.

CoinDesk

20 April 2026

Arbitrum Security Council freezes 30,766 ETH (~$71 million) linked to the exploiter on Arbitrum One, moving funds to an intermediary wallet accessible only through further governance action. The freeze is coordinated with law enforcement.

CoinDesk

21 April 2026

Exploiter begins moving approximately 75,701 ETH (~$175 million) into freshly created Ethereum mainnet addresses and begins routing funds through THORChain, converting ETH to Bitcoin. THORChain volume surges approximately 18x.

Unchained Crypto / CryptoTimes

23 April 2026

Aave rallies DeFi partners to form DeFi United, a coordinated recovery coalition targeting full restoration of rsETH's backing.

CoinDesk

27 April 2026

DeFi United coalition pledges exceed $300 million. Major contributors include Mantle (30,000 ETH), Aave DAO (25,000 ETH), Stani Kulechov personally (5,000 ETH), Ether.fi, Lido, and Kelp DAO.

CoinDesk

May 2026

U.S. District Court for the Southern District of New York issues a temporary restraining order freezing the same 30,766 ETH held by Arbitrum governance, following a legal claim by North Korea terrorism judgment creditors (Han Kim and Yong Seok Kim) under the Foreign Sovereign Immunities Act and Terrorism Risk Insurance Act.

Unchained Crypto

5 May 2026

KelpDAO publishes 'Setting the Record Straight Around the LayerZero Bridge Hack,' citing Telegram screenshots to argue LayerZero personnel reviewed and approved the 1-of-1 DVN setup over 2.5 years and eight integration discussions.

CoinDesk

10 May 2026

LayerZero publishes an updated statement admitting: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions' and 'We own that,' reversing its earlier position that responsibility lay solely with KelpDAO.

CryptoTimes

20 May 2026

LayerZero publishes detailed technical breakdown of the single-verifier flaw behind the exploit and confirms migration of all OApp defaults to a minimum 3/3 DVN configuration, with a target of 5/5.

CryptoTimes
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 31 of 31 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0625 claims checked4 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 7/29/2026, 12:05:57 PM

last updated: 8/26/2026, 6:07:02 AM

5 views

avoid.net — verified advice for a post-truth world