North Korean attackers socially engineered a LayerZero developer to compromise RPC nodes and drain $292 million from KelpDAO, exploiting a single-verifier vulnerability; LayerZero has rebuilt infrastructure and reformed its validator model.
Security & Exploits ·
On April 18, 2026, attackers attributed to the Democratic People's Republic of Korea compromised the KelpDAO bridge built on LayerZero's crosschain messaging protocol, resulting in the theft of approximately $292 million in rsETH tokens. According to LayerZero Labs' incident report, the breach began when an attacker socially engineered a LayerZero developer to obtain session keys, then used those credentials to access the protocol's RPC cloud environment and alter internal nodes. By poisoning these nodes and executing a denial-of-service attack against external providers, the attacker forced LayerZero's signing service to rely on the compromised infrastructure and produce a valid attestation for a forged crosschain message.
The attack succeeded because KelpDAO's implementation required only a single verifier to approve token transfers across chains—a configuration that left no margin for independent validation. Once the attacker obtained one valid signature from LayerZero's Decentralized Verifier Network, the destination contract unlocked the rsETH without additional checks. No other applications, channels, or transactions on the protocol were affected.
LayerZero Labs has since rebuilt its cloud infrastructure with stricter access controls and multi-factor authorization for privileged operations. The protocol's operating stance has also shifted: the LayerZero Labs DVN will no longer serve as the sole required validator on any channel, effectively mandating that applications implement redundant verification. The underlying on-chain protocol remains unchanged, but LayerZero Labs now enforces baseline security requirements as a participant in the validator ecosystem.