← LayerZero — DVN Single-Verifier Configuration Risk1 decision on this page
Audit log
Every state-changing event for LayerZero — DVN Single-Verifier Configuration Risk: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-02 12:28:28ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 443,696,889
- sig
37BR3ymBxf7F…5Bq8Lu92explorer ↗- hash
F5CNXqRe5riK…bUYbXyDbsha256 → base58
verifying row…full verify ↗canonical bytes (35515 B) ▸
{"actor":"system:backfill","investigation_id":"a2160711-45ac-45e2-a1fe-fae89736b49c","kind":"publish","page_slug":"layerzero-dvn-single-verifier-configuration-risk","published_at":"2026-09-02T12:28:28.620Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"LayerZero — DVN Single-Verifier Configuration Risk","sections":[{"content":"LayerZero V2's security model requires each cross-chain message to be verified by one or more Decentralized Verifier Networks (DVNs) before the destination contract acts on it. The protocol's design is permissive by default: application developers (OApp operators) can configure how many DVNs must attest to a message, including a minimum of one. This flexibility means a bridge can be deployed with a single required verifier — a so-called 1-of-1 or 1/1 DVN configuration — creating a single point of failure in which one compromised verifier is sufficient to forge and authenticate any cross-chain message.\n\nKelpDAO's rsETH bridge was configured with exactly this setup. Its sole required DVN was the LayerZero Labs DVN at address 0x589dEDbD617e0CBcB916A9223F4d1300c294236b, with zero optional DVNs. A Blockaid technical analysis confirmed that the attacker's forged message was authenticated exclusively by this single DVN, and that no corresponding source transaction existed on the originating chain (Unichain), meaning the entire $292 million release was triggered by a fabricated packet.\n\nOpenZeppelin's post-incident analysis noted that standard smart contract audits do not typically assess third-party integration configurations or whether external protocol recommendations are followed, meaning the 1-of-1 configuration risk was invisible to KelpDAO's auditors. According to The Defiant, citing Dune Analytics data, approximately 47% of LayerZero OApps were found to use minimal DVN security configurations following the KelpDAO hack, indicating the problem was not isolated to a single protocol.","heading":"DVN Architecture and the 1-of-1 Configuration Risk","severity":"critical","sources":[{"credibility":2,"name":"How a Single LayerZero DVN Compromise Drained $292M from KelpDAO — Blockaid Blog","type":"research","url":"https://blockaid.io/blog/how-a-single-layerzero-dvn-compromise-drained-292m-from-kelpdao"},{"credibility":2,"name":"$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"},{"credibility":2,"name":"Dune Analytics Reveals 47% of LayerZero OApps Use Minimal DVN Security Following KelpDAO Hack — The Defiant","type":"news_article","url":"https://thedefiant.io/news/security/dune-layerzero-oapp-dvn-security-analysis-1bklaq"}]},{"content":"On April 18, 2026, an attacker drained approximately $292 million from KelpDAO's rsETH bridge, making it the largest DeFi exploit of 2026. The attack targeted the LayerZero cross-chain messaging layer rather than any flaw in KelpDAO's or LayerZero's smart contracts; auditors had previously reviewed both without identifying the vulnerability.\n\nAccording to technical analyses by Blockaid and OpenZeppelin, the attack proceeded as follows. The attacker, later attributed to the DPRK-affiliated TraderTraitor unit of the Lazarus Group, compromised RPC nodes supporting the LayerZero Labs DVN — the sole verifier on KelpDAO's bridge. Attackers replaced node software with malicious versions capable of forging responses and used a distributed denial-of-service (DDoS) attack to take down remaining healthy nodes, funneling all DVN traffic through the poisoned infrastructure. The compromised DVN then attested to a forged cross-chain message claiming that 116,500 rsETH had been burned on Unichain, when in fact no source transaction existed. KelpDAO's OFTAdapter contract on Ethereum, operating as designed, released the full amount to the attacker's address.\n\nAt nonce 308, 116,500 rsETH (approximately $292 million at the time) was drained in a single transaction. The attacker attempted a second drain at nonce 309 targeting approximately 40,000 rsETH (~$100 million), but KelpDAO's emergency multisig paused core contracts 46 minutes after the initial drain, blocking the second attempt.\n\nPost-drain, the attacker demonstrated sophisticated DeFi knowledge: stolen rsETH was deposited into Aave V3 as collateral, with approximately $190 million in WETH borrowed against it, creating unliquidatable positions that further disrupted the protocol. Approximately 52,440 ETH was then routed through consolidation addresses and bridged across chains.\n\nThe exploit also triggered cascading effects: rsETH's whitelist status on multiple lending protocols including Aave V3/V4, SparkLend, and Fluid caused those protocols to freeze rsETH markets, amplifying the damage across 20+ networks where the affected escrow backed rsETH deployments.\n\nThe initial compromise of LayerZero's developer infrastructure is reported to have begun as early as March 6, 2026, when an attacker allegedly socially engineered a LayerZero Labs developer to harvest session keys and gain access to LayerZero's RPC cloud environment.","heading":"The KelpDAO rsETH Bridge Exploit — April 2026","severity":"critical","sources":[{"credibility":1,"name":"Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains"},{"credibility":2,"name":"How a Single LayerZero DVN Compromise Drained $292M from KelpDAO — Blockaid Blog","type":"research","url":"https://blockaid.io/blog/how-a-single-layerzero-dvn-compromise-drained-292m-from-kelpdao"},{"credibility":2,"name":"$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"},{"credibility":2,"name":"Inside the KelpDAO Bridge Exploit — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"LayerZero Post Mortem Shows Lazarus Group Stole $290M From KelpDAO via RPC Node Compromise — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/lazarus-kelpdao-290m-layerzero-rpc-hack-da50p3"}]},{"content":"Mandiant, CrowdStrike, and independent security researchers have attributed the KelpDAO bridge exploit to TraderTraitor, a subgroup of the North Korean state-sponsored Lazarus Group, also tracked as UNC4899. LayerZero Labs itself publicly attributed the attack to this group.\n\nThe FBI has previously linked TraderTraitor to the $308 million DMM Bitcoin hack in 2024 and to the $1.5 billion Bybit breach in early 2025. The group is assessed to routinely use social engineering of technology company employees to gain initial access to internal infrastructure before executing large-scale cryptocurrency thefts.\n\nIn the KelpDAO incident, TraderTraitor allegedly targeted a LayerZero Labs developer, compromising the developer's session keys to gain access to LayerZero's RPC cloud environment. Attackers then gained access to the RPC list used by the DVN, compromised two independent RPC nodes running on separate clusters, and swapped out the underlying node binaries with malicious versions. The malicious binaries returned correct responses to LayerZero's monitoring systems while feeding tampered responses to the LayerZero Labs DVN, making the compromise invisible to automated detection until the exploit executed.","heading":"Attribution: DPRK Lazarus Group (TraderTraitor / UNC4899)","severity":"high","sources":[{"credibility":2,"name":"LayerZero Ties KelpDAO Exploit to Lazarus Subgroup TraderTraitor — Yahoo Finance / LayerZero","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/layerzero-ties-kelpdao-exploit-lazarus-071321486.html"},{"credibility":1,"name":"LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"credibility":2,"name":"LayerZero Labs KelpDAO Incident Report — LayerZero (official)","type":"official","url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"}]},{"content":"In the aftermath of the exploit, LayerZero and KelpDAO engaged in a public dispute about which party bore responsibility for the vulnerable 1-of-1 DVN configuration.\n\nLayerZero's initial public statement, published on or around April 20, 2026, asserted that the protocol's integration documentation and direct communications to KelpDAO had recommended a multi-verifier setup. LayerZero argued that KelpDAO chose to use a single-verifier configuration despite those recommendations, and that a properly configured bridge would have required an attacker to compromise multiple independent DVNs simultaneously — a far harder task.\n\nKelpDAO disputed this account. In a response published around May 5, 2026, KelpDAO claimed that LayerZero personnel had reviewed and approved the 1/1 DVN configuration that LayerZero subsequently blamed for the attack. CoinDesk reported that KelpDAO asserted LayerZero's own default settings contributed to the outcome.\n\nOn May 9, 2026, LayerZero reversed its earlier posture, publicly acknowledging it 'made a mistake' in the KelpDAO DVN configuration. According to CoinDesk's reporting, LayerZero stated: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions. We didn't police what our DVN was securing, which created a risk we simply didn't see.' Crypto Times reported LayerZero added: 'We Own That.' No court or regulator has adjudicated the dispute between the parties as of the date of this report, and no settlement terms have been publicly disclosed.","heading":"Dispute Between LayerZero and KelpDAO Over Responsibility","severity":"high","sources":[{"credibility":1,"name":"LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"credibility":1,"name":"Kelp DAO hits back at LayerZero for trying to shift the blame after a massive exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/kelp-dao-claims-layerzero-s-default-settings-are-what-actually-caused-the-usd290-million-disaster"},{"credibility":1,"name":"Kelp says LayerZero approved setup it blamed for $292 million bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"credibility":1,"name":"LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"credibility":2,"name":"LayerZero Says 'We Own That' After $292M Kelp DAO Hack — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/05/10/layerzero-says-we-own-that-after-292m-kelp-dao-hack-admits-security-mistake/"}]},{"content":"On May 18, 2026, LayerZero Labs published a formal incident report detailing the attack and announcing policy changes. The key changes as reported across multiple sources include:\n\n1. The LayerZero Labs DVN will no longer sign or attest messages from any application using a 1/1 DVN configuration, effectively making it impossible for a protocol to use LayerZero Labs as its sole verifier going forward.\n\n2. LayerZero stated that all defaults on all pathways are being migrated to 5/5 where possible, and no less than 3/3 on any chain where only 3 DVNs are available.\n\n3. LayerZero announced it was actively reaching out to projects still using 1-of-1 configurations to facilitate migration to multi-DVN models.\n\nThese changes addressed the immediate configuration risk but do not retroactively eliminate the possibility that non-LayerZero-operated DVNs could still be configured in 1/1 setups by individual protocols using third-party verifiers. The changes also cannot undo the reputational and financial damage sustained from the April 2026 incident.\n\nCritic responses from the crypto community, reported by TradingView, argued that adding more verifiers alone is insufficient if those verifiers share common infrastructure, operators, or software supply chains — a concern the incident illustrated given that LayerZero's own RPC infrastructure was the attack surface.","heading":"LayerZero's Post-Incident Security Changes","severity":"medium","sources":[{"credibility":2,"name":"LayerZero Labs KelpDAO Incident Report — LayerZero (official)","type":"official","url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"},{"credibility":2,"name":"LayerZero Details Single-Verifier Flaw Behind $292M KelpDAO Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/layerzero-details-single-verifier-flaw-behind-292m-kelpdao-exploit/"},{"credibility":2,"name":"KelpDAO Hack Update: LayerZero Details Security Changes After $292M Hack — The Market Periodical","type":"news_article","url":"https://themarketperiodical.com/2026/05/10/kelpdao-hack-update-layerzero-details-security-changes-after-292m-hack/"},{"credibility":2,"name":"Crypto Community Slams LayerZero: More Verifiers Won't Stop The Next $290M Hack — TradingView / NewsBTC","type":"news_article","url":"https://www.tradingview.com/news/newsbtc:484aac8e4094b:0-crypto-community-slams-layerzero-more-verifiers-won-t-stop-the-next-290m-hack/"},{"credibility":2,"name":"LayerZero Labs KelpDAO Incident Report PDF — LayerZero (official)","type":"official","url":"https://layerzero.network/publications/kelpdao-incident-report.pdf"}]},{"content":"On August 21–22, 2026, a separate exploit targeted The Sandbox's LayerZero-powered SAND token bridge. The attacker exploited an approveAndCall function on the SAND omnichain fungible token (OFT) contract to hijack LayerZero delegate permissions, enabling the minting of unbacked SAND tokens on Base and BNB Smart Chain without burning any tokens on the source chain.\n\nThe attacker minted approximately 329.24 trillion unbacked SAND tokens across 703 separate events over approximately five hours. Blockaid estimated the notional face value at roughly $49 billion across more than 400 transactions. However, because the attacker could not fully liquidate the unbacked supply against available market depth, actual losses from backed reserves were limited to approximately $675,000. The Sandbox halted bridging to and from Base and BNB Smart Chain upon discovering the exploit.\n\nThis attack used a different technical vector than the KelpDAO incident — contract-level delegate permission abuse rather than off-chain RPC infrastructure compromise — but similarly exploited insufficient verification controls in a LayerZero integration. The incident occurred several months after LayerZero's announced security changes following KelpDAO, raising questions about the completeness of those remediation efforts across all integrations.\n\nThe attack vector in the Sandbox case has not been publicly attributed to a specific threat actor as of the date of this report.","heading":"The Sandbox (SAND) Bridge Exploit — August 2026","severity":"high","sources":[{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"},{"credibility":2,"name":"Sandbox bridge exploit: 329T SAND minted, $675K stolen — Crypto.news","type":"news_article","url":"https://crypto.news/sandbox-329-trillion-sand-bridge-exploit-675k-stolen/"},{"credibility":2,"name":"The Sandbox Halts Base and BNB Bridges After Exploit Mints $49B in Phantom SAND — Coinpaprika","type":"news_article","url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"},{"credibility":2,"name":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — Crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"}]},{"content":"The KelpDAO exploit triggered a large-scale migration of protocols away from LayerZero to competing cross-chain infrastructure, most notably Chainlink's Cross-Chain Interoperability Protocol (CCIP). By mid-August 2026, publicly announced migrations from LayerZero to Chainlink CCIP had reached approximately $15 billion in secured value, according to reporting from CoinDesk, crypto.news, and en.cryptonomist.ch.\n\nKey migrations reported include: BitGo moving approximately $7.4 billion in Wrapped Bitcoin (WBTC) — the largest single transfer in the migration wave; Mantle shifting its approximately $2.5 billion Super Portal; Lombard transferring over $1 billion in bitcoin-backed assets; Solv Protocol migrating $700 million in tokenized Bitcoin; and Kraken migrating its kBTC product. KelpDAO itself migrated rsETH from LayerZero's OFT standard to Chainlink CCIP following the exploit.\n\nChainlink CCIP's architecture requires a minimum of 16 independent node operators per lane, plus a separate Risk Management Network, contrasting with LayerZero's permissive model that historically allowed as few as one verifier. The exodus has been described in trade press as a significant competitive setback for LayerZero.\n\nLayerZero has not published a public accounting of what share of its total secured value has been affected by departures.","heading":"Broader Market Response: $15 Billion Migration from LayerZero","severity":"high","sources":[{"credibility":1,"name":"BitGo moves $7.4 billion Wrapped Bitcoins to Chainlink CCIP in latest LayerZero exodus — The Block","type":"news_article","url":"https://www.theblock.co/post/410594/bitgo-moves-7-4-billion-wrapped-bitcoins-to-chainlink-ccip-in-latest-layerzero-exodus"},{"credibility":1,"name":"BitGo's WBTC move pushes LayerZero-to-Chainlink tally near $15 billion — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/08/04/bitgo-s-wbtc-move-pushes-layerzero-to-chainlink-tally-near-usd15-billion"},{"credibility":2,"name":"$15B exodus: why crypto is leaving LayerZero for Chainlink — Crypto.news","type":"news_article","url":"https://crypto.news/layerzero-chainlink-exodus-15-billion-bridge-migration/"},{"credibility":1,"name":"The $700 million migration: Why Solv Protocol is ditching LayerZero for Chainlink — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/05/07/solv-drops-layerzero-for-chainlink-ccip-in-usd700-million-tokenized-bitcoin-migration"},{"credibility":2,"name":"After Disputing LayerZero Claims, KelpDAO Prepares Chainlink CCIP Migration — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/after-disputing-layerzero-claims-kelpdao-prepares-chainlink-ccip-migration/"},{"credibility":2,"name":"Kraken Joins Exodus from LayerZero, Adopts Chainlink CCIP — Blockchain.news","type":"news_article","url":"https://blockchain.news/news/kraken-switches-to-chainlink-ccip"}]},{"content":"LayerZero's policy change prevents the LayerZero Labs DVN from acting as a sole verifier, but third-party DVN operators are not bound by the same restriction. Protocols using non-LayerZero-operated DVNs in a 1/1 setup may remain vulnerable. Additionally, on at least two chains where LayerZero Labs is the only available DVN (reported as Dinari and Skale), the architecture structurally limits the achievable redundancy regardless of configuration intent.\n\nThe OpenZeppelin analysis of the KelpDAO incident highlighted a structural gap in the broader DeFi security ecosystem: standard smart contract audits do not evaluate third-party integration configurations, off-chain infrastructure dependencies, or DVN selection decisions. A protocol can pass a comprehensive audit and still be critically exposed through its cross-chain messaging configuration. This means the number of currently vulnerable integrations across all LayerZero-connected bridges is not publicly quantifiable from audit records alone.\n\nThe Dune Analytics data cited by The Defiant found that as of the period following the KelpDAO hack, approximately 47% of LayerZero OApps were using minimal DVN security configurations. It is not publicly known how many of those have since remediated, or whether the LayerZero Labs DVN policy change alone is sufficient to eliminate the residual risk across all active integrations.\n\nLayerZero's own incident report conceded that it 'didn't police what our DVN was securing,' an admission that the protocol's permissive architecture had created security blind spots it did not monitor in practice.","heading":"Ongoing Risk: Residual 1-of-1 Configurations and Audit Blind Spots","severity":"high","sources":[{"credibility":2,"name":"Dune Analytics Reveals 47% of LayerZero OApps Use Minimal DVN Security Following KelpDAO Hack — The Defiant","type":"research","url":"https://thedefiant.io/news/security/dune-layerzero-oapp-dvn-security-analysis-1bklaq"},{"credibility":2,"name":"$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"},{"credibility":2,"name":"LayerZero Details Single-Verifier Flaw Behind $292M KelpDAO Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/layerzero-details-single-verifier-flaw-behind-292m-kelpdao-exploit/"},{"credibility":2,"name":"LayerZero concedes 1/1 DVN mistake as Chainlink gains from bridge security fears — Bitcoin Ethereum News","type":"news_article","url":"https://bitcoinethereumnews.com/tech/layerzero-concedes-1-1-dvn-mistake-as-chainlink-gains-from-bridge-security-fears/"}]}],"sources_used":[{"credibility":1,"name":"LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"credibility":1,"name":"LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"credibility":1,"name":"Kelp DAO hits back at LayerZero for trying to shift the blame after a massive exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/kelp-dao-claims-layerzero-s-default-settings-are-what-actually-caused-the-usd290-million-disaster"},{"credibility":1,"name":"Kelp says LayerZero approved setup it blamed for $292 million bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"credibility":1,"name":"Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains"},{"credibility":1,"name":"The $292 million Kelp DAO exploit shows why crypto bridges are still one of the industry's weakest links — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/21/the-usd292-million-kelp-dao-exploit-shows-why-crypto-bridges-are-still-one-of-the-industry-s-weakest-links"},{"credibility":1,"name":"BitGo's WBTC move pushes LayerZero-to-Chainlink tally near $15 billion — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/08/04/bitgo-s-wbtc-move-pushes-layerzero-to-chainlink-tally-near-usd15-billion"},{"credibility":1,"name":"The $700 million migration: Why Solv Protocol is ditching LayerZero for Chainlink — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/05/07/solv-drops-layerzero-for-chainlink-ccip-in-usd700-million-tokenized-bitcoin-migration"},{"credibility":1,"name":"BitGo moves $7.4 billion Wrapped Bitcoins to Chainlink CCIP in latest LayerZero exodus — The Block","type":"news_article","url":"https://www.theblock.co/post/410594/bitgo-moves-7-4-billion-wrapped-bitcoins-to-chainlink-ccip-in-latest-layerzero-exodus"},{"credibility":2,"name":"LayerZero Labs KelpDAO Incident Report — LayerZero (official blog)","type":"official","url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"},{"credibility":2,"name":"KelpDAO Incident Statement — LayerZero (official blog)","type":"official","url":"https://layerzero.network/blog/kelpdao-incident-statement"},{"credibility":2,"name":"LayerZero Labs KelpDAO Incident Report PDF — LayerZero","type":"official","url":"https://layerzero.network/publications/kelpdao-incident-report.pdf"},{"credibility":2,"name":"How a Single LayerZero DVN Compromise Drained $292M from KelpDAO — Blockaid Blog","type":"research","url":"https://blockaid.io/blog/how-a-single-layerzero-dvn-compromise-drained-292m-from-kelpdao"},{"credibility":2,"name":"$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"},{"credibility":2,"name":"Inside the KelpDAO Bridge Exploit — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"LayerZero Post Mortem Shows Lazarus Group Stole $290M From KelpDAO via RPC Node Compromise — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/lazarus-kelpdao-290m-layerzero-rpc-hack-da50p3"},{"credibility":2,"name":"Dune Analytics Reveals 47% of LayerZero OApps Use Minimal DVN Security Following KelpDAO Hack — The Defiant","type":"research","url":"https://thedefiant.io/news/security/dune-layerzero-oapp-dvn-security-analysis-1bklaq"},{"credibility":2,"name":"LayerZero Ties KelpDAO Exploit to Lazarus Subgroup TraderTraitor — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/layerzero-ties-kelpdao-exploit-lazarus-071321486.html"},{"credibility":2,"name":"LayerZero Links $292 Million Kelp DAO Bridge Exploit to North Korea's Lazarus Group — Unchained","type":"news_article","url":"https://unchainedcrypto.com/layerzero-links-292-million-kelp-dao-bridge-exploit-to-north-koreas-lazarus-group/"},{"credibility":2,"name":"LayerZero details $292M KelpDAO exploit and tightens bridge security — Crypto.news","type":"news_article","url":"https://crypto.news/layerzero-details-292m-kelpdao-exploit-and-tightens-bridge-security/"},{"credibility":2,"name":"LayerZero Details Single-Verifier Flaw Behind $292M KelpDAO Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/layerzero-details-single-verifier-flaw-behind-292m-kelpdao-exploit/"},{"credibility":2,"name":"LayerZero Says 'We Own That' After $292M Kelp DAO Hack — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/05/10/layerzero-says-we-own-that-after-292m-kelp-dao-hack-admits-security-mistake/"},{"credibility":2,"name":"LayerZero concedes 1/1 DVN mistake as Chainlink gains from bridge security fears — Bitcoin Ethereum News","type":"news_article","url":"https://bitcoinethereumnews.com/tech/layerzero-concedes-1-1-dvn-mistake-as-chainlink-gains-from-bridge-security-fears/"},{"credibility":2,"name":"Crypto Community Slams LayerZero: More Verifiers Won't Stop The Next $290M Hack — TradingView / NewsBTC","type":"news_article","url":"https://www.tradingview.com/news/newsbtc:484aac8e4094b:0-crypto-community-slams-layerzero-more-verifiers-won-t-stop-the-next-290m-hack/"},{"credibility":2,"name":"Sandbox bridge exploit: 329T SAND minted, $675K stolen — Crypto.news","type":"news_article","url":"https://crypto.news/sandbox-329-trillion-sand-bridge-exploit-675k-stolen/"},{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"},{"credibility":2,"name":"The Sandbox Halts Base and BNB Bridges After Exploit Mints $49B in Phantom SAND — Coinpaprika","type":"news_article","url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"},{"credibility":2,"name":"$15B exodus: why crypto is leaving LayerZero for Chainlink — Crypto.news","type":"news_article","url":"https://crypto.news/layerzero-chainlink-exodus-15-billion-bridge-migration/"},{"credibility":2,"name":"LayerZero Crypto Migration Sparks $15 Billion Shift to Chainlink — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/20/layerzero-crypto-migration-shift/"},{"credibility":2,"name":"After Disputing LayerZero Claims, KelpDAO Prepares Chainlink CCIP Migration — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/after-disputing-layerzero-claims-kelpdao-prepares-chainlink-ccip-migration/"},{"credibility":2,"name":"KelpDAO Hack Update: LayerZero Details Security Changes After $292M Hack — The Market Periodical","type":"news_article","url":"https://themarketperiodical.com/2026/05/10/kelpdao-hack-update-layerzero-details-security-changes-after-292m-hack/"}],"summary":"LayerZero is a cross-chain messaging protocol whose permissive Decentralized Verifier Network (DVN) architecture allowed integrating protocols to deploy bridges secured by a single verifier. In April 2026, this design pattern was exploited by the DPRK-affiliated Lazarus Group (TraderTraitor unit), which compromised LayerZero Labs' own DVN infrastructure to forge cross-chain messages and drain approximately $292 million from KelpDAO's rsETH bridge — the largest DeFi exploit of 2026. LayerZero has since publicly admitted a mistake in allowing its DVN to operate as a 1-of-1 verifier for high-value transactions and has announced policy changes, but the incident triggered a $15 billion migration of secured value away from LayerZero to competing infrastructure. A separate August 2026 exploit of The Sandbox's LayerZero-powered bridge deepened concerns about systemic risk across LayerZero integrations.","timeline":[{"date":"2026-03-06","event":"Alleged initial compromise: TraderTraitor reportedly socially engineered a LayerZero Labs developer, harvesting session keys and gaining access to LayerZero's RPC cloud environment.","source":"The Defiant / LayerZero incident reporting","source_url":"https://thedefiant.io/news/hacks/lazarus-kelpdao-290m-layerzero-rpc-hack-da50p3"},{"date":"2026-04-18","event":"KelpDAO rsETH bridge drained for approximately $292 million (116,500 rsETH) via a forged cross-chain message authenticated by a single compromised DVN. KelpDAO's emergency multisig paused contracts 46 minutes after the initial drain, blocking a second attempted theft.","source":"CoinDesk / Blockaid / Chainalysis","source_url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains"},{"date":"2026-04-20","event":"LayerZero publishes initial incident statement attributing the exploit to KelpDAO's choice of a 1/1 DVN configuration and to DPRK threat actor TraderTraitor. KelpDAO disputes this account, claiming LayerZero's default settings caused the disaster.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"date":"2026-04-21","event":"CoinDesk analysis published examining why crypto bridges remain one of the industry's weakest links, using the KelpDAO exploit as a case study.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/04/21/the-usd292-million-kelp-dao-exploit-shows-why-crypto-bridges-are-still-one-of-the-industry-s-weakest-links"},{"date":"2026-05-05","event":"KelpDAO publicly claims that LayerZero personnel reviewed and approved the 1/1 DVN configuration that LayerZero blamed for the exploit.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"date":"2026-05-06","event":"KelpDAO announces migration of rsETH from LayerZero's OFT standard to Chainlink CCIP.","source":"Cryptonomist","source_url":"https://en.cryptonomist.ch/2026/05/06/kelp-dao-hack-migration/"},{"date":"2026-05-07","event":"Solv Protocol announces $700 million tokenized Bitcoin migration from LayerZero to Chainlink CCIP.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/05/07/solv-drops-layerzero-for-chainlink-ccip-in-usd700-million-tokenized-bitcoin-migration"},{"date":"2026-05-09","event":"LayerZero publicly admits it 'made a mistake' in the KelpDAO DVN configuration, reversing weeks of blaming KelpDAO. LayerZero states it 'didn't police what our DVN was securing.'","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"date":"2026-05-15","event":"Kraken announces migration from LayerZero to Chainlink CCIP for kBTC and future wrapped assets.","source":"Cryptonomist","source_url":"https://en.cryptonomist.ch/2026/05/15/kraken-chainlink-ccip-migration/"},{"date":"2026-05-18","event":"LayerZero publishes formal incident report (PDF) detailing the attack, attributing it to TraderTraitor, and announcing policy changes including refusing to sign 1/1 DVN configurations and migrating defaults to 5/5 or 3/3 depending on chain.","source":"LayerZero (official)","source_url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"},{"date":"2026-08-04","event":"BitGo moves approximately $7.4 billion in Wrapped Bitcoin (WBTC) from LayerZero to Chainlink CCIP, pushing the total LayerZero-to-Chainlink migration tally near $15 billion.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/08/04/bitgo-s-wbtc-move-pushes-layerzero-to-chainlink-tally-near-usd15-billion"},{"date":"2026-08-21","event":"The Sandbox (SAND) LayerZero-powered bridge exploited. Attacker hijacks LayerZero delegate permissions via an approveAndCall function vulnerability to mint approximately 329 trillion unbacked SAND tokens on Base and BNB Smart Chain over five hours. Actual losses from backed reserves estimated at approximately $675,000.","source":"Crypto.news / BeInCrypto","source_url":"https://crypto.news/sandbox-329-trillion-sand-bridge-exploit-675k-stolen/"},{"date":"2026-08-22","event":"The Sandbox halts bridging to and from Base and BNB Smart Chain following discovery of the exploit.","source":"Coinpaprika","source_url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"},{"date":"2026-08-20","event":"Total publicly announced value migrated from LayerZero to Chainlink CCIP reported at approximately $15 billion.","source":"Cryptonomist","source_url":"https://en.cryptonomist.ch/2026/08/20/layerzero-crypto-migration-shift/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision e9d0b87e-256e-4c80-baa6-e63c095f5d6e
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.