KelpDAO attributes $300M+ hack to DPRK-linked breach of LayerZero infrastructure, exposing widespread 1-1 DVN defaults; migrating to Chainlink CCIP.
Security & Exploits ·
On April 18, 2026, an exploit targeting LayerZero Labs' infrastructure resulted in over $300 million in losses across DeFi protocols, with an additional $100 million in forged transactions blocked after KelpDAO intervened. KelpDAO contests LayerZero's assertion that the incident stemmed from misconfiguration by users, arguing instead that the breach originated within LayerZero's own off-chain infrastructure. According to KelpDAO, threat actors linked to the DPRK with high confidence exploited this infrastructure to fraudulently trigger attestations from LayerZero's Decentralized Verification Network (DVN).
KelpDAO's analysis reveals that the 1-1 DVN security configuration blamed for the breach was not unique to the protocol. Public data shows that approximately 47 percent of LayerZero OApp contracts operated with this same 1-1 setup, with over 90 percent of LayerZero messages using the LayerZero Labs DVN in their configuration. The protocol's official documentation and templates default to recommending this configuration with LayerZero Labs as the sole required verifier, meaning many projects followed the recommended guidance that KelpDAO asserts LayerZero itself had confirmed as secure.
KelpDAO announced a migration to Chainlink CCIP to address the vulnerability exposure. Notably, LayerZero published its postmortem more than 34 hours after the incident, leaving the bridging infrastructure operational during that interval despite KelpDAO's earlier detection and notification.