LayerZero attributes $292M KelpDAO bridge hack to Lazarus Group
Security & Exploits ·
LayerZero says a forged verification message, not a broken bridge, let North Korea's Lazarus Group drain KelpDAO's cross-chain bridge over the weekend.
Attackers drained roughly $292 million from KelpDAO's cross-chain bridge on Saturday, pulling 116,500 rsETH, a liquid restaking token backed by staked ether, according to a preliminary analysis LayerZero published Monday, which called the attack "likely" the work of Lazarus Group's TraderTraitor subunit, Decrypt reported. TraderTraitor has previously been linked to the Axie Infinity Ronin Bridge and WazirX compromises.
The bridge itself was not broken; attackers corrupted the channel that verifies it. KelpDAO had relied on a single verifier to approve transfers in and out of the bridge, a setup LayerZero said it had repeatedly urged the project to abandon in favor of multiple verifiers. Attackers tapped two of the lines that verifier used to confirm withdrawals on Unichain, fed those lines a fake confirmation, then knocked the remaining lines offline so the verifier had no choice but to rely on the compromised inputs. Cyvers CTO Meir Dolev described the mechanism as tricking "the one party whose word opened the door," and said the attackers came within three minutes of draining another $100 million before a rapid blacklist cut them off. Cyvers stopped short of confirming the Lazarus attribution itself, noting that some patterns match DPRK-linked operations in sophistication and coordination but that no wallet clustering tied to the group has been confirmed.
The malicious node software was built to erase itself once the attack finished, wiping binaries and logs to obscure the trail both in real time and afterward, according to Cyvers' analysis.
The exploit set off broader withdrawals across DeFi, pulling more than $10 billion out of lending protocol Aave. In the same cluster of events, Lido paused EarnETH deposits and deployed a $3 million first-loss buffer after the exploit exposed $21.6 million in rsETH, and the Arbitrum Security Council froze 30,766 ETH connected to the exploit following coordination with law enforcement, according to an Arbitrum post. Separate figures put total value locked declines at 11% for Ethereum and 42% for Mantle within 24 hours.
LayerZero said it will stop approving messages for any application still running a single-verifier setup, though it has not detailed a timeline or how existing integrations will be affected. Cyvers' hesitation to confirm the Lazarus attribution alongside LayerZero's own claim leaves the identity of the attackers formally unresolved, and the scope of the frozen funds' eventual recovery or return remains unclear.