The post $290M KelpDAO Hack SHOCK: LayerZero Points to Fatal DVN Flaw, Lazarus Suspected appeared on BitcoinEthereumNews.com. Key Takeaways: KelpDAO was exploitedThe post $290M KelpDAO Hack SHOCK: LayerZero Points to Fatal DVN Flaw, Lazarus Suspected appeared on BitcoinEthereumNews.com. Key Takeaways: KelpDAO was exploited

$290M KelpDAO Hack SHOCK: LayerZero Points to Fatal DVN Flaw, Lazarus Suspected

2026/04/20 16:54
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Key Takeaways:

  • KelpDAO was exploited to the tune of approximately $290M in a targeted attack involving a more advanced attacker, most likely a Lazarus Group.
  • The attack took advantage of a single-DVN configuration, which poses a critical point of failure.
  • LayerZero assures zero impact on other apps, and the incident is completely segregated.

The cross-chain security has been questioned by a large-scale DeFi exploit due to the KelpDAO becoming a victim of one of the highest exploits in 2026. LayerZero has published a breakdown that describes the core issue and refutes the allegations of a protocol-level weakness.

KelpDAO Exploit Breakdown

On April 18, an attack on the rsETH system of KelpDAO cost the organization about $290 million. LayerZero indicates that there was no exploit of smart contract bugs or key leakage.

Rather, attackers targeted infrastructure, namely RPC nodes of the verifier system of LayerZero.

They hacked into select RPC endpoints and overwrote their binaries with malicious applications. These nodes passed on incorrect transaction information to the verifier, but they still reported regular information elsewhere, hence covering up this attack in real time.

Attackers put down an RPC node in healthy condition using DDoS attack to accomplish the operation. This manoeuvre compelled the system to switch to the compromised nodes, losing the validity of real cross-chain messages and accepting the fake ones.

Read More: $7.6M DeFi Exploit Rocks Rhea Finance as Hackers Manipulate Pools in Hours

Single DVN Setup Created the Weak Point

The server problem was rooted in KelpDAO’s decision on how the server should be configured.

Why the Setup Failed

The system depends on a single verification (1-of-1 DVN) without a backup layer or independent verification. Due to the lack of redundancy and no scheme to identify or check fake data, manipulated information is still acceptable as legitimate.

LayerZero emphasized that it has consistently recommended a multi-DVN model. Under that setup, multiple independent verifiers must agree before a transaction is accepted.

Advanced Tactics Linked to Lazarus

The attack shows a new level of sophistication. LayerZero attributes it to a state-backed group, likely North Korea’s Lazarus (TraderTraitor unit). Techniques used include:

  • RPC data poisoning with selective responses
  • Coordinated DDoS to trigger failover
  • Self-destructing malware to erase evidence

Such techniques enabled the attackers to evade surveillance mechanisms and instead perform unfazed during the period of exploitation.

Immediate Actions Taken

Requirements are now being tight in the LayerZero ecosystem:

  • It will no longer support single-DVN configurations
  • Projects are being encouraged to switch to multi-DVN designs
  • Law enforcement agencies are involved in the investigation
  • Ongoing monitoring activities to reclaim stolen amounts

A change in attack patterns was evident in the incident. Rather than cracking code, attackers are going after infrastructure and poorly configured areas, which despite often being neglected, are equally of high priority.

Read More: Resolv Burns 46M USR After $80M Exploit, Wipes Out Illicit Supply in Major Recovery Push

Source: https://www.cryptoninjas.net/news/290m-kelpdao-hack-shock-layerzero-points-to-fatal-dvn-flaw-lazarus-suspected/

시장 기회
CROSS 로고
CROSS 가격(CROSS)
$0.12432
$0.12432$0.12432
-3.97%
USD
CROSS (CROSS) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Roll the Dice & Win Up to 1 BTC

Roll the Dice & Win Up to 1 BTCRoll the Dice & Win Up to 1 BTC

Invite friends & share 500,000 USDT!