LayerZero Breaks Silence On $290 Million KelpDAO Crypto Exploit

bitcoinistОпубліковано о 2026-04-20Востаннє оновлено о 2026-04-20

Анотація

LayerZero has addressed the $290 million exploit affecting KelpDAO's rsETH, asserting it was not a protocol failure but a result of KelpDAO's decision to use a single-DVN (Decentralized Verifier Network) configuration. The company claims the attack was isolated to this specific setup and confirms no contagion risk to other assets or applications. Preliminary analysis suggests the attack was executed by a sophisticated state actor, likely North Korea's Lazarus Group. The method involved poisoning RPC infrastructure used by the LayerZero Labs DVN, swapping binaries on compromised nodes, and using DDoS attacks to force traffic to the malicious infrastructure. However, LayerZero states its least-privilege principles prevented a direct compromise. The exploit was only possible due to KelpDAO's 1-of-1 verifier setup, which contradicts LayerZero's recommended multi-DVN redundancy model. A properly configured system with multiple independent DVNs would have prevented the attack. LayerZero has deprecated affected nodes, restored its DVN, and will no longer support 1/1 configurations. Aave has frozen rsETH and WETH reserves on its platforms as a precaution while confirming rsETH on Ethereum mainnet remains fully backed.

KelpDAO’s $290 million rsETH exploit has moved into a new phase, with LayerZero and Aave now publicly outlining how the incident unfolded, why the damage appears contained, and what it could mean for crypto cross-chain security standards going forward.

The central claim from LayerZero is that the exploit was not a failure of the protocol itself, but the result of KelpDAO’s decision to run rsETH with a single-DVN configuration. That matters because the latest statements shift the market narrative away from generalized contagion risk across LayerZero-integrated assets and toward a narrower question: how much risk was concentrated in one application’s security design.

LayerZero Links KelpDAO Crypto Exploit To RPC Attack

In an incident statement from April 20, LayerZero said the April 18 attack targeted KelpDAO’s rsETH setup and was “isolated entirely to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup.” The company added that it had conducted “a comprehensive review of active integrations” and could confirm “with confidence that there is zero contagion to any other asset or application.”

LayerZero framed the episode as a state-linked crypto infrastructure attack rather than a protocol exploit. According to the statement, “preliminary indicators suggest attribution to a highly-sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor.”

It said the attack did not compromise the protocol, key management, or the DVN instances directly. Instead, the attacker allegedly poisoned downstream RPC infrastructure used by the LayerZero Labs DVN, swapped binaries on compromised op-geth nodes, and then used DDoS pressure on uncompromised RPCs to force failover toward the poisoned infrastructure.

That sequence is central to LayerZero’s argument. “Because of our least-privilege principles, they were unable to compromise the actual DVN instances,” the company wrote. “However, they used this pivot point to execute an RPC-spoofing attack.

Their malicious node used a custom payload designed explicitly to forge a message to the DVN with minimal warnings.” LayerZero said the manipulated node presented false data only to the DVN while returning truthful responses to other IPs, including its own monitoring infrastructure, in what it described as a deliberately stealthy effort to avoid detection.

Even so, LayerZero argues the exploit should have been stopped at the application layer had rsETH not relied on a 1-of-1 verifier setup. “The affected application was rsETH, issued by KelpDAO,” the statement said. “Their OApp configuration at the time of this incident relied on a 1-of-1 DVN setup, with LayerZero Labs as the sole verifier — a configuration that directly contradicts the multi-DVN redundancy model that LayerZero has consistently recommended to all integration partners.”

It added that “a properly hardened configuration would have required consensus across multiple independent DVNs, rendering this attack ineffective even in the event of any single DVN being compromised.”

The company said its DVN is live again, that affected RPC nodes have been deprecated and replaced, and that it will no longer sign or attest messages for applications using a 1/1 configuration. It also said it is working with law enforcement and industry partners, including Seal911, to track funds.

Aave said in an X update on late The protocol said its analysis shows “rsETH on Ethereum mainnet is fully backed,” but added that “out of an abundance of caution, rsETH remains frozen across Aave V3 and V4 and exposure to the incident is capped.” WETH reserves also remain frozen across the affected markets on Ethereum, Arbitrum, Base, Mantle, and Linea while the team continues to validate information and assess possible resolutions.

At press time, the total crypto market cap stood at $2.5 trillion.

Total crypto market cap must overcome the 0.786 Fib, 1-week chart | Source: TOTAL on TradingView.com

Пов'язані питання

QWhat was the main reason for the $290 million KelpDAO crypto exploit according to LayerZero?

ALayerZero stated that the exploit was not a failure of its protocol but was the result of KelpDAO's decision to run its rsETH with a single-DVN (Decentralized Verifier Network) configuration, which contradicted LayerZero's recommended multi-DVN redundancy model.

QWhich sophisticated state actor is LayerZero preliminarily attributing the attack to?

ALayerZero's preliminary indicators suggest the attack is attributed to a highly-sophisticated state actor, likely the Lazarus Group from the Democratic People's Republic of Korea (DPRK), and more specifically, the subgroup known as TraderTraitor.

QHow did the attacker execute the RPC-spoofing attack without compromising the DVN instances directly?

AThe attacker poisoned downstream RPC infrastructure used by the LayerZero Labs DVN, swapped binaries on compromised op-geth nodes, and then used DDoS pressure on uncompromised RPCs to force failover toward the poisoned infrastructure, allowing them to forge a message to the DVN.

QWhat action has LayerZero taken regarding applications using a 1-of-1 DVN configuration after the incident?

ALayerZero announced that it will no longer sign or attest messages for any applications using a 1-of-1 DVN configuration, reinforcing its stance that a multi-DVN setup is necessary for security.

QWhat is the current status of rsETH on Aave V3 and V4 markets following the exploit?

AAave has stated that, out of an abundance of caution, rsETH remains frozen across its Aave V3 and V4 markets, and exposure to the incident is capped, although their analysis shows that rsETH on Ethereum mainnet is fully backed.

Пов'язані матеріали

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

Facing massive paper losses exceeding $90 billion each amidst a sharp market downturn, "Digital Asset Treasury" (DAT) giants Strategy and Bitmine find themselves in a precarious position, but with different underlying risks. Strategy, heavily invested in Bitcoin (BTC), faces significant financial strain. Its strategy relies heavily on debt, including convertible notes and preferred stock (STRC) requiring substantial dividend payments. With its cash reserves dwindling and BTC offering no staking yield for cash flow, Strategy's high leverage makes it vulnerable. A continued price decline could force asset sales to meet obligations, potentially creating a negative feedback loop. Its market value has already fallen sharply. In contrast, Bitmine, an Ethereum (ETH) holder, appears on firmer financial ground. It primarily funds its purchases through equity offerings (like ATM programs), avoiding debt pressure. It also generates income by staking a large portion of its ETH holdings. While not immune to market drops and shareholder dilution concerns, Bitmine maintains more flexibility, recently announcing a new preferred share offering to raise further capital. The core divergence lies in their financing: Bitmine uses equity (investor money), while Strategy uses debt (borrowed money). Consequently, Bitmine currently faces less immediate liquidity pressure than Strategy, which must navigate the dual challenge of servicing debt/dividends and a declining core asset (BTC) price.

marsbit9 хв тому

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

marsbit9 хв тому

Where the AI Bubble Really Is: Which Layer of Players Are Naked

AI Bubble: Where It Really Is and Who's Swimming Naked This analysis dissects the AI industry not as a single entity but as a five-layer pyramid, arguing that bubbles are concentrated in specific tiers, not uniformly distributed. **Key Distinction from the 2000 Dot-com Bubble:** Unlike 2000, where companies had stock prices before revenue, today's leading AI players have massive, contract-backed revenue driving their valuations. Core infrastructure demand is real, with every GPU running at full capacity for paying customers. **The Five-Layer Pyramid & Bubble Assessment:** * **L0 (Fab/Manufacturing) & Top L4 (Leading AI Apps): NO BUBBLE.** Companies like TSMC, NVIDIA, major cloud providers (Microsoft, Google, Meta, Amazon), and top AI labs have real revenues and orders. Supply is tightly constrained by TSMC's disciplined capacity control and physical limits like power/land for data centers, preventing a supply glut. * **L1 (Memory): BATTLEGROUND.** Sky-high HBM margins could signal a new structural cycle or a classic "boom before bust." The oligopoly of three major players may enforce supply discipline, making this a high-stakes bet. * **L2 (Interconnect/Optical Modules): BUBBLE TERRITORY.** Companies like Lumentum and AAOI have seen stock surges (4-10x) far outpacing revenue growth. This hardware segment has lower physical barriers to expansion than fabs, allowing speculation. It mirrors the 2000 bubble's epicenter—optics. * **L3 (Infrastructure/"GPU Landlords"): VULNERABLE.** GPU leasing companies profit from the current compute shortage but own no long-term moat. Their business model relies on a temporary bottleneck that will ease as big tech expands and new tech (e.g., potential space-based data centers) emerges. * **L4 Long Tail (VC-backed Startups): STRONG BUBBLE SIGNALS.** VC funding concentration in AI is twice that of the 1999 peak. Many startups with little revenue use the valuation logic of successful giants to justify their own, creating high risk of a "valuation crunch" when funding dries up. **Critical Risks to Monitor:** 1. **GPU Depreciation & Accounting:** Companies extending the assumed useful life of GPUs artificially boost profits. The true economic life depends on future generational leaps from NVIDIA. 2. **"GPU Credit" & Off-Balance-Sheet Leverage:** Emerging structures where shell companies borrow to buy GPUs and lease them out (with chipmakers sometimes investing) move debt off major balance sheets. This echoes the "vendor financing" of 2000 and the securitization risks of 2008, though currently small-scale. 3. **TSMC Abandoning Caution:** If the primary supply bottleneck (TSMC's conservative capacity planning) breaks, runaway supply could trigger a bust. 4. **Algorithmic Efficiency Breakthrough:** A major leap in software efficiency could drastically reduce the need for raw compute hardware, undermining the investment thesis. **Conclusion:** The AI boom is expensive and has frothy areas, but its core is underpinned by real demand and physical supply constraints. The bubble risk is layered: most present in optical components, GPU leasing, and the long-tail startup ecosystem, while the foundational chip manufacturing and leading application layers remain relatively solid—for now.

marsbit21 хв тому

Where the AI Bubble Really Is: Which Layer of Players Are Naked

marsbit21 хв тому

Торгівля

Спот
Ф'ючерси
活动图片