LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit

bitcoinistОпубліковано о 2026-04-20Востаннє оновлено о 2026-04-20

Анотація

LayerZero has addressed the $290 million exploit affecting KelpDAO's rsETH, asserting it was not a protocol failure but a result of KelpDAO's decision to use a single-DVN (Decentralized Verifier Network) configuration. The company claims the attack was isolated to this specific setup and confirms no contagion risk to other assets or applications. Preliminary analysis suggests the attack was executed by a sophisticated state actor, likely North Korea's Lazarus Group. The method involved poisoning RPC infrastructure used by the LayerZero Labs DVN, swapping binaries on compromised nodes, and using DDoS attacks to force traffic to the malicious infrastructure. However, LayerZero states its least-privilege principles prevented a direct compromise. The exploit was only possible due to KelpDAO's 1-of-1 verifier setup, which contradicts LayerZero's recommended multi-DVN redundancy model. A properly configured system with multiple independent DVNs would have prevented the attack. LayerZero has deprecated affected nodes, restored its DVN, and will no longer support 1/1 configurations. Aave has frozen rsETH and WETH reserves on its platforms as a precaution while confirming rsETH on Ethereum mainnet remains fully backed.

KelpDAO’s $290 million rsETH exploit has moved into a new phase, with LayerZero and Aave now publicly outlining how the incident unfolded, why the damage appears contained, and what it could mean for crypto cross-chain security standards going forward.

The central claim from LayerZero is that the exploit was not a failure of the protocol itself, but the result of KelpDAO’s decision to run rsETH with a single-DVN configuration. That matters because the latest statements shift the market narrative away from generalized contagion risk across LayerZero-integrated assets and toward a narrower question: how much risk was concentrated in one application’s security design.

LayerZero Links KelpDAO Crypto Exploit To RPC Attack

In an incident statement from April 20, LayerZero said the April 18 attack targeted KelpDAO’s rsETH setup and was “isolated entirely to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup.” The company added that it had conducted “a comprehensive review of active integrations” and could confirm “with confidence that there is zero contagion to any other asset or application.”

LayerZero framed the episode as a state-linked crypto infrastructure attack rather than a protocol exploit. According to the statement, “preliminary indicators suggest attribution to a highly-sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor.”

It said the attack did not compromise the protocol, key management, or the DVN instances directly. Instead, the attacker allegedly poisoned downstream RPC infrastructure used by the LayerZero Labs DVN, swapped binaries on compromised op-geth nodes, and then used DDoS pressure on uncompromised RPCs to force failover toward the poisoned infrastructure.

That sequence is central to LayerZero’s argument. “Because of our least-privilege principles, they were unable to compromise the actual DVN instances,” the company wrote. “However, they used this pivot point to execute an RPC-spoofing attack.

Their malicious node used a custom payload designed explicitly to forge a message to the DVN with minimal warnings.” LayerZero said the manipulated node presented false data only to the DVN while returning truthful responses to other IPs, including its own monitoring infrastructure, in what it described as a deliberately stealthy effort to avoid detection.

Even so, LayerZero argues the exploit should have been stopped at the application layer had rsETH not relied on a 1-of-1 verifier setup. “The affected application was rsETH, issued by KelpDAO,” the statement said. “Their OApp configuration at the time of this incident relied on a 1-of-1 DVN setup, with LayerZero Labs as the sole verifier — a configuration that directly contradicts the multi-DVN redundancy model that LayerZero has consistently recommended to all integration partners.”

It added that “a properly hardened configuration would have required consensus across multiple independent DVNs, rendering this attack ineffective even in the event of any single DVN being compromised.”

The company said its DVN is live again, that affected RPC nodes have been deprecated and replaced, and that it will no longer sign or attest messages for applications using a 1/1 configuration. It also said it is working with law enforcement and industry partners, including Seal911, to track funds.

Aave said in an X update on late The protocol said its analysis shows “rsETH on Ethereum mainnet is fully backed,” but added that “out of an abundance of caution, rsETH remains frozen across Aave V3 and V4 and exposure to the incident is capped.” WETH reserves also remain frozen across the affected markets on Ethereum, Arbitrum, Base, Mantle, and Linea while the team continues to validate information and assess possible resolutions.

At press time, the total crypto market cap stood at $2.5 trillion.

Total crypto market cap must overcome the 0.786 Fib, 1-week chart | Source: TOTAL on TradingView.com

Пов'язані питання

QWhat was the main reason for the $290 million KelpDAO crypto exploit according to LayerZero?

ALayerZero stated that the exploit was not a failure of its protocol but was the result of KelpDAO's decision to run its rsETH with a single-DVN (Decentralized Verifier Network) configuration, which contradicted LayerZero's recommended multi-DVN redundancy model.

QWhich sophisticated state actor is LayerZero preliminarily attributing the attack to?

ALayerZero's preliminary indicators suggest the attack is attributed to a highly-sophisticated state actor, likely the Lazarus Group from the Democratic People's Republic of Korea (DPRK), and more specifically, the subgroup known as TraderTraitor.

QHow did the attacker execute the RPC-spoofing attack without compromising the DVN instances directly?

AThe attacker poisoned downstream RPC infrastructure used by the LayerZero Labs DVN, swapped binaries on compromised op-geth nodes, and then used DDoS pressure on uncompromised RPCs to force failover toward the poisoned infrastructure, allowing them to forge a message to the DVN.

QWhat action has LayerZero taken regarding applications using a 1-of-1 DVN configuration after the incident?

ALayerZero announced that it will no longer sign or attest messages for any applications using a 1-of-1 DVN configuration, reinforcing its stance that a multi-DVN setup is necessary for security.

QWhat is the current status of rsETH on Aave V3 and V4 markets following the exploit?

AAave has stated that, out of an abundance of caution, rsETH remains frozen across its Aave V3 and V4 markets, and exposure to the incident is capped, although their analysis shows that rsETH on Ethereum mainnet is fully backed.

Пов'язані матеріали

Hyperliquid, Wall Street's All-Day Trading Convenience Store

**Hyperliquid: Wall Street's 24/7 Trading Convenience Store** Written by Vicky Ge Huang, Wall Street Journal. Hyperliquid, a decentralized crypto trading platform, has become a go-to venue for Wall Street traders, especially during weekends when traditional U.S. markets are closed. Operating 24/7, it allows traders to pre-position or close trades ahead of market opens, capitalizing on events like geopolitical news. The platform, founded by former Hudson River Trading quant Jeff Yan, offers perpetual contracts on a wide range of assets, including Bitcoin, the S&P 500, oil, and even pre-IPO companies like SpaceX. Its growth exemplifies the merging of traditional finance and crypto markets, attracting significant volume from professional traders seeking leverage and constant access. A key differentiator, according to Yan, is user self-custody of assets—a necessity highlighted by the FTX collapse. Despite U.S. regulatory restrictions, some American users reportedly access the platform via VPN, drawn by its ease of use, lack of stringent KYC, and strong community culture on platforms like Discord and X. The platform is not without risks. Perpetual contracts are complex and highly leveraged, leading to massive liquidations during market volatility. Hyperliquid itself saw $10 billion in liquidations during a market crash in October last year. Regulatory warnings emphasize insufficient risk disclosure for retail investors. With about 11 employees, Hyperliquid and its associated blockchain reportedly generated around $800 million in revenue last year. Its native token, HYPE, has surged over 100% since late 2024. The platform plans to expand into prediction markets and options trading, aiming to become a hub for all financial activity.

foresightnews_api4 хв тому

Hyperliquid, Wall Street's All-Day Trading Convenience Store

foresightnews_api4 хв тому

Former Bankless Member Lucas: Why I Still Bullish on Ethereum

Former Bankless member Lucas explains why he remains bullish on Ethereum despite widespread pessimism. He acknowledges ETH's poor price performance over the past five years compared to Bitcoin and traditional markets, but draws parallels to historical multi-year consolidations seen in tech giants like Amazon and NVIDIA before major breakouts. Fundamentally, Ethereum is stronger than ever: record-high daily transactions (2.27 million in May 2026), significantly lower average gas fees ($0.27), over 400 million total addresses, and more than 32% of ETH staked, securing the network. Lucas's core thesis remains unchanged: all valuable assets will eventually be tokenized, Ethereum will become the primary settlement layer for these assets, and ETH will capture the resulting value. This transition is already underway. Stablecoins, the first proven tokenized real-world asset (RWA), have a $300+ billion market cap, with 54% settled on Ethereum. The broader RWA sector has surpassed $30 billion, with over 53% deployed on Ethereum. He compares the current RWA adoption phase to early DeFi in 2019-20, suggesting immense growth potential. Key catalysts like the potential passage of the U.S. CLARITY Act in 2026 could accelerate institutional adoption. While other blockchains will share the market, Lucas argues that traditional finance prioritizes Ethereum's security, stability, and established ecosystem for trillion-dollar asset tokenization. He concludes that as global assets migrate on-chain, the market will reprice ETH accordingly.

foresightnews_api7 хв тому

Former Bankless Member Lucas: Why I Still Bullish on Ethereum

foresightnews_api7 хв тому

Trump's 'Bitcoin Retirement Plan' Hits Roadblock: Democrats Claim It Endangers American Workers' Pensions?

Democratic Senators Bernie Sanders (I-VT) and Elizabeth Warren (D-MA), along with Rep. Bobby Scott (D-VA), are urging the Labor Department to repeal a proposed rule that would open U.S. retirement savings accounts, like 401(k) plans, to investments in Bitcoin and other cryptocurrencies. In a letter to Acting Labor Secretary Keith Sonderling, they argue the rule would endanger workers' financial futures and contradicts long-standing legal precedents under the Employee Retirement Income Security Act (ERISA). The rule, stemming from a Trump executive order, would shift the legal standard for plan fiduciaries. Instead of requiring them to prove they conducted due diligence on volatile assets, it would presume prudence if they followed a specified process. The lawmakers warn this exposes the $14.2 trillion in 401(k) savings to highly volatile and less-regulated assets, citing FINRA warnings on crypto's risks and FBI data on massive crypto scam losses. The letter also alleges a conflict of interest, noting that President Trump's adult children manage the family's crypto business, which has raised billions. They claim the rule could allow the Trump family to profit at the expense of workers and retirees. Consumer advocates echo concerns that it could turn retirement savings into a lifeline for a risky industry. The Trump administration defends the rule as expanding worker choice, with officials stating it ends the department "picking winners and losers" and requires fiduciaries to follow a prudent process.

foresightnews_api11 хв тому

Trump's 'Bitcoin Retirement Plan' Hits Roadblock: Democrats Claim It Endangers American Workers' Pensions?

foresightnews_api11 хв тому

Rules Change Mid-Game, Polymarket’s Billion-Dollar Bitcoin Prediction Market Mired in Settlement Controversy

A nearly $150 million prediction market contract on Polymarket is in turmoil after the platform refused to settle in favor of traders who correctly predicted that MicroStrategy (now Strategy) would sell Bitcoin. The core dispute revolves around a sale of 32 BTC, which occurred between May 26-31 but was officially disclosed in an SEC 8-K filing on June 1. The original contract stated it would resolve to "Yes" if Strategy sold any Bitcoin before May 31, 11:59 PM ET, using public disclosures and on-chain data as proof. After the filing on June 1, traders who saw the disclosure rushed to buy "Yes" contracts, believing it was conclusive evidence. However, Polymarket's operators later added a rule that the disclosure itself must occur by the deadline, not just the transaction, invalidating the filing as proof. This retroactive rule change has sparked accusations of market manipulation, leaving traders like "willo2," who invested $527,000, facing total losses. The controversy highlights a deeper structural flaw in Polymarket's decentralized settlement system, which relies on UMA's optimistic oracle. Disputed resolutions are ultimately decided by a vote among UMA token holders, a mechanism critics say is vulnerable to manipulation by large holders ("whales") who can vote in their own financial interest rather than on objective facts. Data suggests a high concentration of voting power and significant overlap between voters and Polymarket traders. The dispute emerges as prediction markets like Polymarket and Kalshi are experiencing massive growth and seeking mainstream financial legitimacy, having recently secured regulatory approval from the U.S. CFTC. However, the incident underscores the unresolved tension between decentralized, token-vote-based settlement and the need for transparent, rules-based outcomes in high-stakes financial contracts.

foresightnews_api14 хв тому

Rules Change Mid-Game, Polymarket’s Billion-Dollar Bitcoin Prediction Market Mired in Settlement Controversy

foresightnews_api14 хв тому

Торгівля

Спот
Ф'ючерси
活动图片