Fact-check findings
What an automated fact-checker found when it re-read KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
3 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #15[disputed][awaiting moderator]in section: Fund Movement and Laundering Infrastructure
“One source estimated that approximately $1.2 billion — 85% of stolen funds from North Korea's two H1 2026 attacks combined — flowed through THORChain.”
reviewerOne source estimated approximately $1.2 billion — 85% of stolen funds from North Korea's two H1 2026 attacks combined — flowed through THORChain.This figure is not found in the cited source and is mathematically inconsistent with the page's own reported $577M total for the two 2026 DPRK attacks (85% of $577M is ~$490M, not $1.2B). The $1.2 billion figure appears elsewhere in reporting only in connection with the separate, larger 2025 Bybit hack — the claim as written appears to conflate the two events.Proposed correction (not yet applied)One source estimated that a large share of North Korea's Bybit theft proceeds (over $1.2 billion, from the separate 2025 Bybit hack) flowed through THORChain, though no independently verifiable figure ties an $1.2 billion/85% THORChain flow specifically to the two combined H1 2026 attacks (which totaled roughly $577 million). - #16[disputed][awaiting moderator]in section: Fund Movement and Laundering Infrastructure
“Approximately $75 million of the total stolen amount had been frozen across Arbitrum as a result of coordinated action with law enforcement.”
reviewerThe Arbitrum Security Council froze 30,766 ETH (~$71 million) on April 20, 2026; approximately $75 million of the total stolen amount had been frozen across Arbitrum as a result of coordinated action with law enforcement.This is an internal inconsistency: every other reference on the page (summary, sections[4] itself earlier, sections[5], timeline) consistently states the Arbitrum freeze was ~$71 million / $71.1 million for the same 30,766 ETH. This one sentence states $75 million, which does not match any source consulted.Proposed correction (not yet applied)Approximately $71 million of the total stolen amount had been frozen across Arbitrum as a result of coordinated action with law enforcement. - #18[disputed][awaiting moderator]in section: Industry Recovery — DeFi United
“Contributors included Mantle (30,000 ETH via credit facility), Aave DAO (25,000 ETH pending governance vote), Stani Kulechov personally (5,000 ETH), Ether.fi (5,000 ETH), Lido Finance (2,500 stETH), Kelp DAO (2,000 ETH), Golem Foundation (1,000 ETH), and the Arbitrum Security Council's frozen 30,766 ETH.”
reviewerAave service providers organized 'DeFi United'; contributors included Mantle (30,000 ETH), Aave DAO (25,000 ETH), Kulechov personally (5,000 ETH), Ether.fi (5,000 ETH), Lido (2,500 stETH), Kelp DAO (2,000 ETH), Golem Foundation (1,000 ETH), and the Arbitrum Security Council's frozen 30,766 ETH.The page conflates two distinct ETH pools: (1) fresh pledges from Arbitrum DAO and Consensys (~30,000 ETH each, per DLNews/Unchained), and (2) the Arbitrum Security Council's already-frozen 30,766 ETH tied up in the exploit recovery, which was not proposed for release into DeFi United until a May 1, 2026 governance vote — a date after the 'late April 2026' snapshot this section describes, and one complicated by the SDNY TRO the page itself later describes. As written, the page overstates the frozen ETH's role as an active DeFi United contribution and omits Consensys's separate 30,000 ETH pledge.Proposed correction (not yet applied)Contributors included Mantle (30,000 ETH via credit facility), Aave DAO (25,000 ETH pending governance vote), Stani Kulechov personally (5,000 ETH), Ether.fi (5,000 ETH), Lido Finance (2,500 stETH), Kelp DAO (2,000 ETH), Golem Foundation (1,000 ETH), and Arbitrum DAO (30,000 ETH); the Arbitrum Security Council's separately frozen 30,766 ETH was not released into DeFi United until a governance vote opened May 1, 2026, and was complicated by a competing federal court claim.
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #25[unverifiable][awaiting moderator]reviewerKelpDAO's founding, history, and pre-exploit protocol background.Not a claim on the page; listed here only to cross-reference the coverage_gaps entry on KelpDAO's background.
stale
1 claimThe claim was accurate when written but events since have overtaken it.
- #19[stale][awaiting moderator]in section: Industry Recovery — DeFi United
“As of late April 2026, the effort had gathered over $238 million in committed or contributed assets and was ongoing.”
reviewerAs of late April 2026, the DeFi United effort had gathered over $238 million in committed or contributed assets and was ongoing.The $238M figure itself is accurate as of its April 27, 2026 publication date, but the page nowhere reports that the crisis was subsequently resolved — rsETH was fully restored and DeFi United's recovery plan completed by late May 2026, per multiple sources dated after the page's own most-recently-archived citations (through August 2026). This is a significant unreported resolution, not merely a minor staleness.Proposed correction (not yet applied)As of late April 2026, the effort had gathered over $238 million in committed or contributed assets; the recovery effort was completed roughly five weeks after the exploit, with Kelp DAO announcing on May 26, 2026 that rsETH's backing had been fully restored and normal mint, redemption, and reward operations had resumed.
partially supported
3 claimsThe cited evidence supports part of the claim but not all of it.
- #7[partially supported][awaiting moderator]in section: DVN Configuration and the 1-of-1 Single Point of Failure
“Data at the time of the hack showed that approximately 47% of the roughly 2,665 active LayerZero OApps were using 1-of-1 DVN configurations, representing over $4.5 billion in exposed value.”
reviewerApproximately 47% of the roughly 2,665 active LayerZero OApps used 1-of-1 DVN configurations at the time of the hack, representing over $4.5 billion in exposed value.The headline 47% statistic is corroborated by multiple outlets citing a Dune Analytics breakdown, but the precise '2,665 active OApps' and '$4.5 billion exposed' figures could not be independently verified in any source consulted. - #11[partially supported][awaiting moderator]in section: Downstream Contagion — Aave Bad Debt and DeFi Panic
“Following the theft of 116,500 rsETH, the attacker supplied a substantial portion of the stolen tokens as collateral on Aave V3, borrowing approximately 126,000 WETH (worth approximately $236 million at the time), effectively creating a large undercollateralized position.”
reviewerThe attacker supplied stolen tokens as collateral on Aave V3, borrowing approximately 126,000 WETH (worth approximately $236 million).The 126,000 WETH/$236M figure is reported by some outlets, but a competing, similarly credible figure (89,567 rsETH collateral / ~82,650 WETH borrowed, ~$190M) is also widely reported and not reconciled by the page; the page presents one figure as settled fact without noting the discrepancy. - #20[partially supported][awaiting moderator]in section: Industry Recovery — DeFi United
“LayerZero separately pledged $23 million to DeFi United following its later partial admission of fault.”
reviewerLayerZero separately pledged $23 million to DeFi United following its later partial admission of fault.The $23 million figure is the reported dollar-equivalent value of a 10,000 ETH commitment (split 5,000/5,000 between the DeFi United fund and Aave directly), not a standalone $23M pledge; the page's phrasing is a simplification that could mislead on the actual structure of the pledge.
confirmed
17 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in section: Attack Overview and Timeline
“At approximately 17:35 UTC on Saturday, April 18, 2026, an attacker drained 116,500 rsETH (approximately $292 million) from KelpDAO's LayerZero Omnichain Fungible Token (OFT) bridge — the single largest DeFi exploit of 2026.”
reviewerAt approximately 17:35 UTC on April 18, 2026, an attacker drained 116,500 rsETH (~$292 million) from KelpDAO's LayerZero OFT bridge via RPC node compromise and DDoS-forced DVN failover.Independently corroborated by Chainalysis, LayerZero's own incident report, and multiple news outlets. - #2[confirmed][no action needed]in section: Attack Overview and Timeline
“The attacker came within three minutes of stealing an additional $95–100 million before KelpDAO's emergency pauser multisig froze the protocol's core contracts at 18:21 UTC — 46 minutes after the initial drain. Two follow-up attack attempts at 18:26 and 18:28 UTC reverted without success. KelpDAO publicly acknowledged the incident on social media at approximately 20:10 UTC, nearly three hours after the initial drain.”
reviewerThe attacker came within three minutes of stealing an additional $95–100 million before KelpDAO's pauser multisig froze contracts at 18:21 UTC, 46 minutes after the drain; two follow-up attempts at 18:26 and 18:28 UTC reverted; KelpDAO acknowledged the incident at 20:10 UTC.Timestamps (17:35, 18:21, 18:26/18:28, 20:10 UTC) all independently corroborated by search aggregation of CoinDesk/QuillAudits/Blockaid reporting. - #3[confirmed][no action needed]in section: Attack Overview and Timeline
“The breach had been preceded by a social engineering campaign beginning March 6, 2026, in which attackers harvested session keys from a LayerZero Labs developer, enabling them to pivot into LayerZero's RPC cloud environment and plant the poisoned nodes.”
reviewerThe breach was preceded by a social engineering campaign beginning March 6, 2026, harvesting session keys from a LayerZero Labs developer to access LayerZero's RPC cloud and plant poisoned nodes.Confirmed by LayerZero's own official incident report. - #4[confirmed][no action needed]in section: DVN Configuration and the 1-of-1 Single Point of Failure
“LayerZero's initial April 19, 2026 postmortem stated the incident resulted from 'Kelp's security choices rather than LayerZero's code' and that the 1-of-1 DVN configuration 'directly contradicts' its recommended multi-DVN security model.”
reviewerLayerZero's initial April 19, 2026 postmortem placed responsibility on KelpDAO's 1-of-1 DVN configuration, which 'directly contradicts' its recommended multi-DVN model.Confirmed against LayerZero's own official statement. - #5[confirmed][no action needed]in section: DVN Configuration and the 1-of-1 Single Point of Failure
“However, KelpDAO published a counter-memo titled 'Setting the Record Straight Around the LayerZero Bridge Hack' on or around May 5, 2026, citing Telegram screenshots in which a LayerZero team member had stated 'No problem on using defaults either' regarding the verifier configuration.”
reviewerKelpDAO's May 5, 2026 counter-memo cited Telegram screenshots showing a LayerZero team member said 'No problem on using defaults either,' and claimed LayerZero reviewed/approved the setup over 2.5 years and eight integration discussions.Consistent with CoinDesk and secondary reporting on the Kelp/LayerZero blame dispute. - #6[confirmed][no action needed]in section: DVN Configuration and the 1-of-1 Single Point of Failure
“A security researcher from Spearbit, Sujith Somraaj, alleged he had submitted a bug bounty describing this exact attack pattern, which LayerZero rejected.”
reviewerSujith Somraaj (Spearbit) alleged he submitted a bug bounty describing the exact attack pattern, which LayerZero rejected.Corroborated: LayerZero spokesperson stated 'Sujith is correct, 1/1 config is out of scope of the bug bounty program.' - #8[confirmed][no action needed]in section: DVN Configuration and the 1-of-1 Single Point of Failure
“On or around May 10, 2026, LayerZero published an updated statement acknowledging: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions' and 'We own that,' reversing its earlier position that sole responsibility lay with KelpDAO.”
reviewerOn or around May 10, 2026, LayerZero published an updated statement acknowledging 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions' and 'We own that,' and subsequently banned 1-of-1 configurations, migrating defaults toward 5/5 with a 3/3 floor.Exact quotes verified. Note CoinDesk dated the statement May 9 while CryptoTimes (the page's cited source) dated it May 10 — both plausible given rolling coverage; not flagged as an error. - #9[confirmed][no action needed]in section: Attribution — Lazarus Group / TraderTraitor (DPRK)
“Security firm Cyvers declined to make the same attribution, noting that while certain operational patterns matched DPRK operations, no definitive wallet clustering had confirmed the connection as of publication.”
reviewerLayerZero attributed the attack with preliminary confidence to Lazarus Group / TraderTraitor; TRM Labs corroborated, tracing funding to a Wu Huihui-controlled Bitcoin wallet from 2018 and to BTCTurk hack proceeds; Cyvers declined to make the same attribution.All attribution details (LayerZero preliminary, TRM corroboration, Cyvers dissent, Wu Huihui/BTCTurk funding chain) independently confirmed. - #10[confirmed][no action needed]in section: Attribution — Lazarus Group / TraderTraitor (DPRK)
“TRM Labs reported that this single attack, combined with the April 1, 2026 Drift Protocol hack ($285 million), meant North Korea was responsible for approximately $577 million in stolen crypto through April 2026 — 76% of all global crypto hack losses in H1 2026 across a total loss pool of approximately $759 million, achieved via just two attacks.”
reviewerTRM Labs reported that KelpDAO plus the April 1, 2026 Drift Protocol hack ($285 million) meant North Korea was responsible for ~$577 million, or 76% of H1 2026 global crypto hack losses (~$759 million total), via just two attacks; cumulative DPRK theft since 2017 exceeded $6 billion; North Korea publicly denied this.TRM Labs report and North Korea's denial both directly verified against primary/near-primary sources. - #12[confirmed][no action needed]in section: Downstream Contagion — Aave Bad Debt and DeFi Panic
“Aave modeled its potential bad debt exposure at between $124 million and $230 million, depending on how KelpDAO chose to distribute losses: if spread across all rsETH holders, rsETH would face an estimated 15% depeg resulting in approximately $124 million in bad debt; if losses were isolated to Layer 2 networks, bad debt could reach approximately $230 million. Some sources cited the final bad debt figure as approximately $177 million.”
reviewerAave modeled bad debt at $124M (15% depeg, losses spread across all rsETH holders) to $230M (losses isolated to L2 networks); some sources cited a final figure of ~$177 million.Both bad-debt scenarios and the $177M alternate figure are independently verified; page appropriately hedges with 'some sources cited.' - #13[confirmed][no action needed]in section: Downstream Contagion — Aave Bad Debt and DeFi Panic
“The broader DeFi market reacted with alarm; reports cited over $10 billion in withdrawals from Aave as participants panicked. Aave founder Stani Kulechov confirmed that Aave's own contracts were not compromised and that the exploit was external.”
reviewerReports cited over $10 billion in withdrawals from Aave as participants panicked; Aave founder Stani Kulechov confirmed Aave's own contracts were not compromised and the exploit was external.Both the $10B withdrawal figure and Kulechov's statement independently corroborated. - #14[confirmed][no action needed]in section: Fund Movement and Laundering Infrastructure
“TRM Labs reported that THORChain had 'processed the vast majority of proceeds from both the Bybit breach (2025) and the KelpDAO hack (2026), converting hundreds of millions in stolen ETH to Bitcoin.'”
reviewerOn April 21, 2026, the exploiter moved ~75,701 ETH (~$175M) into new addresses; THORChain was the primary laundering venue, with ~$80M routed through it; TRM Labs said THORChain 'processed the vast majority of proceeds from both the Bybit breach (2025) and the KelpDAO hack (2026), converting hundreds of millions in stolen ETH to Bitcoin.'Quote matches TRM Labs reporting verbatim; supporting figures (75,701 ETH/$175M, $80M via THORChain) independently corroborated by Unchained and CryptoTimes. - #17[confirmed][no action needed]in section: Legal and Regulatory Response
“On May 1, 2026, the U.S. District Court for the Southern District of New York issued a temporary restraining order freezing approximately 30,766 ETH (worth approximately $71.1 million) — the same assets already frozen by Arbitrum's Security Council — following a legal claim by families holding unpaid terrorism judgments against North Korea.”
reviewerOn May 1, 2026, SDNY issued a TRO freezing the same 30,766 ETH (~$71.1M) following a claim by terrorism judgment creditors Han Kim and Yong Seok Kim, holding judgments exceeding $877 million, under FSIA and TRIA.Fully confirmed against source, including the plaintiffs' names, amounts, and legal statutes. - #21[confirmed][no action needed]in section: Systemic Implications — Bridge Security and Decentralization
“OpenZeppelin published an analysis titled '$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit,' highlighting that the attack succeeded without exploiting any smart contract vulnerability.”
reviewerOpenZeppelin published '$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit,' noting the attack succeeded without exploiting any smart contract vulnerability.Exact title and thesis independently verified by direct fetch of the source. - #22[confirmed][no action needed]in section: Systemic Implications — Bridge Security and Decentralization
“KelpDAO announced it would migrate to Chainlink's CCIP infrastructure following the event.”
reviewerKelpDAO announced it would migrate to Chainlink's CCIP infrastructure following the event.Independently confirmed by The Block and multiple other outlets. - #23[confirmed][no action needed]in section: Systemic Implications — Bridge Security and Decentralization
“The exploit was the second of two state-sponsored North Korean attacks within 18 days in April 2026; the Drift Protocol hack ($285 million) on April 1 preceded it by 17 days, and TRM Labs identified that attackers in both incidents staged their operations over weeks or months before executing rapidly.”
reviewerThe exploit was the second of two state-sponsored North Korean attacks within 18 days in April 2026; the Drift Protocol hack ($285 million) on April 1 preceded it by 17 days.Date arithmetic (April 1 to April 18 = 17 days) is correct and confirmed against TRM Labs. - #24[confirmed][no action needed]in section: DVN Configuration and the 1-of-1 Single Point of Failure
“LayerZero: KelpDAO Incident Statement (official blog)”
reviewerThe official LayerZero blog posts cited as sources ('KelpDAO Incident Statement' and 'LayerZero Labs KelpDAO Incident Report') exist and support the page's characterizations.Both official LayerZero URLs were fetched directly and are live, current, and consistent with how the page cites them; no link rot detected. Note: a distinct third official post ('An Overdue Apology' at layerzero.network/blog/an-overdue-apology) also exists covering the May admission but is not cited on the page — not an error, but could be added for completeness.