LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit

bitcoinist2026-04-20 tarihinde yayınlandı2026-04-20 tarihinde güncellendi

Özet

LayerZero has addressed the $290 million exploit affecting KelpDAO's rsETH, asserting it was not a protocol failure but a result of KelpDAO's decision to use a single-DVN (Decentralized Verifier Network) configuration. The company claims the attack was isolated to this specific setup and confirms no contagion risk to other assets or applications. Preliminary analysis suggests the attack was executed by a sophisticated state actor, likely North Korea's Lazarus Group. The method involved poisoning RPC infrastructure used by the LayerZero Labs DVN, swapping binaries on compromised nodes, and using DDoS attacks to force traffic to the malicious infrastructure. However, LayerZero states its least-privilege principles prevented a direct compromise. The exploit was only possible due to KelpDAO's 1-of-1 verifier setup, which contradicts LayerZero's recommended multi-DVN redundancy model. A properly configured system with multiple independent DVNs would have prevented the attack. LayerZero has deprecated affected nodes, restored its DVN, and will no longer support 1/1 configurations. Aave has frozen rsETH and WETH reserves on its platforms as a precaution while confirming rsETH on Ethereum mainnet remains fully backed.

KelpDAO’s $290 million rsETH exploit has moved into a new phase, with LayerZero and Aave now publicly outlining how the incident unfolded, why the damage appears contained, and what it could mean for crypto cross-chain security standards going forward.

The central claim from LayerZero is that the exploit was not a failure of the protocol itself, but the result of KelpDAO’s decision to run rsETH with a single-DVN configuration. That matters because the latest statements shift the market narrative away from generalized contagion risk across LayerZero-integrated assets and toward a narrower question: how much risk was concentrated in one application’s security design.

LayerZero Links KelpDAO Crypto Exploit To RPC Attack

In an incident statement from April 20, LayerZero said the April 18 attack targeted KelpDAO’s rsETH setup and was “isolated entirely to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup.” The company added that it had conducted “a comprehensive review of active integrations” and could confirm “with confidence that there is zero contagion to any other asset or application.”

LayerZero framed the episode as a state-linked crypto infrastructure attack rather than a protocol exploit. According to the statement, “preliminary indicators suggest attribution to a highly-sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor.”

It said the attack did not compromise the protocol, key management, or the DVN instances directly. Instead, the attacker allegedly poisoned downstream RPC infrastructure used by the LayerZero Labs DVN, swapped binaries on compromised op-geth nodes, and then used DDoS pressure on uncompromised RPCs to force failover toward the poisoned infrastructure.

That sequence is central to LayerZero’s argument. “Because of our least-privilege principles, they were unable to compromise the actual DVN instances,” the company wrote. “However, they used this pivot point to execute an RPC-spoofing attack.

Their malicious node used a custom payload designed explicitly to forge a message to the DVN with minimal warnings.” LayerZero said the manipulated node presented false data only to the DVN while returning truthful responses to other IPs, including its own monitoring infrastructure, in what it described as a deliberately stealthy effort to avoid detection.

Even so, LayerZero argues the exploit should have been stopped at the application layer had rsETH not relied on a 1-of-1 verifier setup. “The affected application was rsETH, issued by KelpDAO,” the statement said. “Their OApp configuration at the time of this incident relied on a 1-of-1 DVN setup, with LayerZero Labs as the sole verifier — a configuration that directly contradicts the multi-DVN redundancy model that LayerZero has consistently recommended to all integration partners.”

It added that “a properly hardened configuration would have required consensus across multiple independent DVNs, rendering this attack ineffective even in the event of any single DVN being compromised.”

The company said its DVN is live again, that affected RPC nodes have been deprecated and replaced, and that it will no longer sign or attest messages for applications using a 1/1 configuration. It also said it is working with law enforcement and industry partners, including Seal911, to track funds.

Aave said in an X update on late The protocol said its analysis shows “rsETH on Ethereum mainnet is fully backed,” but added that “out of an abundance of caution, rsETH remains frozen across Aave V3 and V4 and exposure to the incident is capped.” WETH reserves also remain frozen across the affected markets on Ethereum, Arbitrum, Base, Mantle, and Linea while the team continues to validate information and assess possible resolutions.

At press time, the total crypto market cap stood at $2.5 trillion.

Total crypto market cap must overcome the 0.786 Fib, 1-week chart | Source: TOTAL on TradingView.com

İlgili Sorular

QWhat was the main reason for the $290 million KelpDAO crypto exploit according to LayerZero?

ALayerZero stated that the exploit was not a failure of its protocol but was the result of KelpDAO's decision to run its rsETH with a single-DVN (Decentralized Verifier Network) configuration, which contradicted LayerZero's recommended multi-DVN redundancy model.

QWhich sophisticated state actor is LayerZero preliminarily attributing the attack to?

ALayerZero's preliminary indicators suggest the attack is attributed to a highly-sophisticated state actor, likely the Lazarus Group from the Democratic People's Republic of Korea (DPRK), and more specifically, the subgroup known as TraderTraitor.

QHow did the attacker execute the RPC-spoofing attack without compromising the DVN instances directly?

AThe attacker poisoned downstream RPC infrastructure used by the LayerZero Labs DVN, swapped binaries on compromised op-geth nodes, and then used DDoS pressure on uncompromised RPCs to force failover toward the poisoned infrastructure, allowing them to forge a message to the DVN.

QWhat action has LayerZero taken regarding applications using a 1-of-1 DVN configuration after the incident?

ALayerZero announced that it will no longer sign or attest messages for any applications using a 1-of-1 DVN configuration, reinforcing its stance that a multi-DVN setup is necessary for security.

QWhat is the current status of rsETH on Aave V3 and V4 markets following the exploit?

AAave has stated that, out of an abundance of caution, rsETH remains frozen across its Aave V3 and V4 markets, and exposure to the incident is capped, although their analysis shows that rsETH on Ethereum mainnet is fully backed.

İlgili Okumalar

55TB to 28TB? The Rumor and Panic Behind Rubin's Memory Being Halved

Title: 55TB to 28TB? The Rumor and Panic Behind the Potential Halving of Rubin's Memory. On June 4th, a report from SemiAnalysis suggested NVIDIA's next-gen Vera Rubin NVL72 AI rack may ship with roughly 28TB of SOCAMM DRAM per rack instead of the anticipated 55TB, primarily using 96GB modules. This sparked a market panic, causing Micron's stock to drop over 10% on fears of halved memory demand. However, the article argues this panic is misguided for several key reasons. First, SOCAMM modules are socketed and upgradeable, not soldered. Lower initial configuration doesn't mean permanent demand loss. Second, the primary driver is a severe 2026 LPDDR5X supply shortage, not diminished need. NVIDIA is likely prioritizing rack shipments with available components. Third, with fixed total LPDDR5X supply, using less per rack could allow NVIDIA to ship *more* racks, not necessarily reducing overall memory orders. Micron's sharp drop was also attributed to a broader semiconductor sell-off triggered by Broadcom's earnings, with the SemiAnalysis report providing a convenient narrative for profit-taking after Micron's massive rally. In summary: the report on lower default configurations is likely accurate, but interpreting it as a demand collapse is wrong. The real risk for Micron lies in its reportedly minimal HBM4 share for Rubin, not in potentially flexible SOCAMM demand. The sell-off appears more like a correction amplified by coinciding negative catalysts.

marsbit14 dk önce

55TB to 28TB? The Rumor and Panic Behind Rubin's Memory Being Halved

marsbit14 dk önce

Exclusive from Yingke | Tang Wenbin's 'Yuanli Lingji' Merges with Logistics Robotics Company, and Secures Investment from Zhipu, SenseTime, Jieyue, and Others

Exclusive report: Embodied AI company "Yuanli Lingji" recently completed a new round of financing from major AI model firms including Zhipu AI, Stepfun, and SenseTime, alongside continued investments from industrial backers like Huaqin and SAIC Hengxu. Founded in March 2025 by Tang Wenbin, former co-founder and CTO of Megvii, Yuanli Lingji is a general-purpose embodied AI model company. In a notable move, the company has merged with logistics robotics firm "Atomix" (formerly known as Yuanli Juhe) through a share acquisition. Atomix, which originated from Megvii's logistics robotics business led by Tang in 2016 and was spun off in July 2024, has grown to become the world's second-largest supplier of pallet shuttle robots, with annual revenue nearing 1 billion RMB and over 500 projects globally for clients like Uniqlo and CATL. This merger aims to break the industry's "data deadlock" by combining Atomix's extensive real-world operational data from more than 20 countries with Yuanli Lingji's model training capabilities. The company's embodied AI model "DM0" utilizes a cross-domain training approach, integrating internet semantics, autonomous driving rules, and robotics data to achieve hardware-agnostic, precise manipulation even with a compact 2.4B parameter size. The collective investment from key AI players and the strategic merger signal a shift in the competitive landscape, as major model companies pivot from language tokens to physical actions ("from Token to Action"). The industry is entering a consolidation phase where hardware, AI models, data, and application scenarios converge to scale embodied intelligence, a trend mirrored by recent moves from giants like ByteDance and Skild AI.

marsbit22 dk önce

Exclusive from Yingke | Tang Wenbin's 'Yuanli Lingji' Merges with Logistics Robotics Company, and Secures Investment from Zhipu, SenseTime, Jieyue, and Others

marsbit22 dk önce

U.S. Stock Market Trends: Dow Hits New High, Nasdaq Falls, Whom Did Broadcom's Slap Wake Up?

U.S. Stocks Split: Dow Hits Record High as Nasdaq Slips; Broadcom's Plunge Sparks Rotation On June 4, the U.S. stock market saw a sharp divergence. The Dow Jones surged 875 points (+1.73%) to a record high of 51,561.93, while the Nasdaq Composite edged down 0.09%. The S&P 500 rose 0.41%. The primary catalyst was a sharp sell-off in AI-related chip stocks, led by Broadcom (AVGO). Despite reporting a 143% year-over-year jump in AI semiconductor revenue to $10.8 billion, the company's shares plunged about 14%. This was triggered by its maintained long-term AI revenue target, which failed to meet heightened expectations for a stock that had gained 55% this quarter and traded at a high P/E ratio. The slide dragged down the broader semiconductor sector and the technology板块. Conversely, money rotated into sectors like Healthcare (+3.14%), Financials (+2.67%), and Real Estate (+1.87%). UnitedHealth and Goldman Sachs were major contributors to the Dow's gains. The rotation was attributed to a search for value outside overheated tech names and a slight dip in Treasury yields. In other major news, SpaceX confirmed its IPO for June 12, targeting a record $75 billion raise at a ~$1.75 trillion valuation. Additionally, initial jobless claims rose to a four-month high, adding nuance to the labor market narrative ahead of the key May non-farm payrolls report. The day's action signaled that while the AI growth story remains intact, excessive valuations are prompting a market reassessment. Funds are moving, at least temporarily, from high-flying tech to more defensive and value-oriented sectors. The sustainability of this rotation hinges on upcoming economic data, particularly the jobs report, and the market's absorption of the massive SpaceX IPO.

marsbit25 dk önce

U.S. Stock Market Trends: Dow Hits New High, Nasdaq Falls, Whom Did Broadcom's Slap Wake Up?

marsbit25 dk önce

From 'Old Dogs' to 'New Darlings': How AI is Revaluing Old Infrastructure, from Dell to Nokia

"Old Dogs" Become AI's New Darlings: Revaluing Legacy Infrastructure The AI investment narrative is shifting. Beyond the spotlight on core chipmakers like Nvidia, a new wave of interest is rising for legacy tech companies—Dell, HPE, Nokia, Cisco, Corning, Western Digital—once labeled as slow-growth, outdated stories. This resurgence stems from AI's evolution from model development to real-world deployment, creating massive demand for physical infrastructure. As AI moves into data center construction and enterprise adoption, the focus turns to who can actually build and deliver complex systems. These established players hold decades of experience in supply chains, integration, networking, and enterprise delivery—assets now critical for scaling AI. The revaluation can be grouped into three key infrastructure areas: 1. **Servers & Integration (e.g., Dell, HPE):** They are becoming essential system integrators, transforming GPUs into full-scale AI servers with networking, power, and cooling, then delivering them to clients. Strong recent earnings and AI-specific revenue/order growth for Dell and HPE underscore this shift. 2. **Networking & Connectivity (e.g., Corning, Nokia, Cisco):** As AI clusters grow, high-speed data transfer becomes paramount. Corning benefits from fiber demand for data center links, Nokia is exploring AI-integrated wireless networks (AI-RAN), and Cisco sees surging orders for data center switches—all critical for efficient AI operations. 3. **Storage (e.g., Western Digital, Seagate):** The AI data explosion requires vast capacity. Beyond high-speed memory (HBM), there's growing need for high-capacity HDDs to store training data, logs, video, and cold/archival data cost-effectively. This revaluation, however, is not a blanket endorsement. True reassessment requires concrete proof: AI-driven orders and revenue growth, upward revisions to company guidance, and sustainable improvements in profit quality, not just top-line sales. In essence, AI is not turning all old tech firms into high-growth stocks; it is selectively re-pricing the "old assets" of companies that are mission-critical for building the new AI infrastructure, transforming their legacy capabilities into renewed growth engines.

marsbit34 dk önce

From 'Old Dogs' to 'New Darlings': How AI is Revaluing Old Infrastructure, from Dell to Nokia

marsbit34 dk önce

İşlemler

Spot
Futures
活动图片