KelpDAO's LayerZero-powered cross-chain bridge adapter was exploited on April 18, resulting in the loss of approximately $292 million in rsETH tokens. The breach drained 116,500 rsETH from the Omnichain Fungible Token adapter on Ethereum, representing roughly 18% of the token's circulating supply. Cascading withdrawals exceeding $10 billion followed across DeFi protocols including Aave in the hours immediately after the attack.
The Single-Verifier Weakness
The core vulnerability centered on KelpDAO's bridge configuration, which used a 1-of-1 Decentralized Verifier Network (DVN). This architecture required only one validator, operated by LayerZero Labs, to authenticate cross-chain transactions. Attackers exploited this by forging a message claiming that rsETH had been burned on Unichain. With only a single validator needed to approve the transaction, the forged message was sufficient to trigger the release of reserves on Ethereum.
Attack Methodology
The exploitation combined infrastructure compromise with network disruption. Attackers compromised LayerZero's internal RPC nodes by replacing legitimate binaries with counterfeit versions designed to provide false data to the sole DVN validator. Simultaneously, they launched a distributed denial-of-service (DDoS) attack against external nodes, forcing the system into failover mode where the compromised nodes became the only available source of transaction verification.
KelpDAO's emergency multisignature team paused core contracts approximately 46 minutes after the attack began at 18:21 UTC, preventing a follow-up attempt targeting an additional 40,000 rsETH.
Attribution and Recovery
Preliminary analysis linked the attack to North Korea's Lazarus Group, specifically its TraderTraitor subgroup, based on the attack's sophistication and methodology. Partial recovery efforts have recovered approximately $71 million, roughly a quarter of the stolen funds.
Implications for Bridge Security
The incident highlights the risk posed by minimal validator requirements in cross-chain systems. Protocols currently using LayerZero's OFT standard are reassessing their DVN configurations. A 2-of-3 or 3-of-5 validator setup would have required attackers to simultaneously compromise multiple independent validators, substantially increasing the difficulty of such an attack.


