Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

KelpDAO Bridge Exploit Results in $292M rsETH Drain Through Single-Verifier Vulnerability

A cross-chain bridge adapter vulnerability exposed a critical flaw in KelpDAO's security architecture, allowing attackers to drain approximately $292 million in rsETH tokens by exploiting a system that relied on a single validator to authenticate transactions.
2 hours ago 7 views
KelpDAO Bridge Exploit Results in $292M rsETH Drain Through Single-Verifier Vulnerability

KelpDAO's LayerZero-powered cross-chain bridge adapter was exploited on April 18, resulting in the loss of approximately $292 million in rsETH tokens. The breach drained 116,500 rsETH from the Omnichain Fungible Token adapter on Ethereum, representing roughly 18% of the token's circulating supply. Cascading withdrawals exceeding $10 billion followed across DeFi protocols including Aave in the hours immediately after the attack.

The Single-Verifier Weakness

The core vulnerability centered on KelpDAO's bridge configuration, which used a 1-of-1 Decentralized Verifier Network (DVN). This architecture required only one validator, operated by LayerZero Labs, to authenticate cross-chain transactions. Attackers exploited this by forging a message claiming that rsETH had been burned on Unichain. With only a single validator needed to approve the transaction, the forged message was sufficient to trigger the release of reserves on Ethereum.

Attack Methodology

The exploitation combined infrastructure compromise with network disruption. Attackers compromised LayerZero's internal RPC nodes by replacing legitimate binaries with counterfeit versions designed to provide false data to the sole DVN validator. Simultaneously, they launched a distributed denial-of-service (DDoS) attack against external nodes, forcing the system into failover mode where the compromised nodes became the only available source of transaction verification.

KelpDAO's emergency multisignature team paused core contracts approximately 46 minutes after the attack began at 18:21 UTC, preventing a follow-up attempt targeting an additional 40,000 rsETH.

Attribution and Recovery

Preliminary analysis linked the attack to North Korea's Lazarus Group, specifically its TraderTraitor subgroup, based on the attack's sophistication and methodology. Partial recovery efforts have recovered approximately $71 million, roughly a quarter of the stolen funds.

Implications for Bridge Security

The incident highlights the risk posed by minimal validator requirements in cross-chain systems. Protocols currently using LayerZero's OFT standard are reassessing their DVN configurations. A 2-of-3 or 3-of-5 validator setup would have required attackers to simultaneously compromise multiple independent validators, substantially increasing the difficulty of such an attack.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $78,777.86-0.46% EthereumETH $2,502.63+0.47% Tether USDUSDT $0.9998-0.03% BNBBNB $753.52+1.89% XRPXRP $1.44+3.46% USDCUSDC $1.00-0.01% SolanaSOL $104.37+0.59% TRONTRX $0.3390+1.34% HyperliquidHYPE $84.46-0.67% ZcashZEC $1,179.85+1.77%
Prices by Coinranking. Informational only.