LayerZero on Monday blamed North Korea’s Lazarus Group for the $292 million KelpDAO bridge exploit that shook DeFi markets on April 18, saying the attack succeeded because KelpDAO ran its bridge with a single verifier — a configuration LayerZero had warned against before launch. The incident is the largest DeFi hack of 2026.
A DeFi protocol is a financial application that runs on a blockchain without a central operator, allowing users to lend, borrow, and trade digital assets through automated code. The KelpDAO exploit showed how a flaw in the infrastructure connecting those applications across different blockchains can cascade into billion-dollar damage.
- An attacker drained 116,500 rsETH — about 18% of circulating supply — from KelpDAO’s LayerZero-powered bridge on April 18, 2026, extracting roughly $292 million in under 46 minutes.
- LayerZero attributed the attack with preliminary confidence to North Korea’s Lazarus Group and its TraderTraitor subunit, saying two RPC nodes used by LayerZero’s verifier were compromised with malicious software.
- The vulnerability traced to KelpDAO’s use of a 1-of-1 DVN (decentralized verifier network) configuration — a single point of failure that LayerZero says it had previously recommended against in its integration documentation.
- Aave V3 and V4 froze rsETH collateral after attackers deposited stolen tokens to borrow WETH, leaving the protocol with an estimated $177 million in bad debt spread across Ethereum and Arbitrum.
Published: April 20, 2026 14:00 UTC
How the attack worked
At 17:35 UTC on April 18, an attacker began minting rsETH on Ethereum mainnet with no real backing. The mechanism was a forged LayerZero cross-chain message — a digital instruction that KelpDAO’s bridge treated as legitimate because it appeared to carry proper verifier approval.
LayerZero’s cross-chain messaging relies on DVNs, or decentralized verifier networks, to confirm that a message sent from one chain actually originated on another. A DVN is an independent service that attests to the validity of a cross-chain transaction before funds move. KelpDAO’s bridge used only one DVN, meaning a single compromised attestation was enough to authorize the release of 116,500 rsETH.
According to LayerZero’s post-mortem, attackers compromised two RPC nodes — the servers that LayerZero’s verifier queried to check transaction validity — and replaced the software running on them with malicious versions that falsely confirmed a fraudulent transaction had taken place. “A properly hardened configuration would have required consensus across multiple independent DVNs, rendering this attack ineffective even in the event of any single DVN being compromised,” LayerZero wrote in a statement on April 20.
LayerZero said it had communicated multi-verifier recommendations to KelpDAO directly and listed them in its public integration documentation. Every other application on the protocol running multi-verifier setups was unaffected. LayerZero has since blocked all 1-of-1 DVN configurations from signing messages.
Damage across DeFi lending markets
The attacker did not sell the stolen rsETH directly. Selling 18% of a token’s supply would have crashed the price and recovered far less. Instead, the attacker deposited 116,500 rsETH into Aave V3 as collateral and borrowed roughly 74,000 WETH against it — extracting hard assets while leaving rsETH’s inflated collateral value to collapse onto Aave’s balance sheet.
Aave froze rsETH markets on V3 and V4 within hours. Co-founder Stani Kulechov confirmed Aave’s own contracts were not compromised. But the bad debt was already recorded. Aave’s Umbrella WETH safety vault on Ethereum — a reserve pool designed to absorb shortfalls — was completely drained at approximately $56 million. Governance is now weighing a proposal to issue around $120 million in new AAVE tokens to cover the remaining deficit, which would dilute existing token holders.
Aave’s total value locked dropped from $45.8 billion before the attack to $35.7 billion as of April 20, according to Aavescan data. SparkLend, Fluid, and Upshift also halted rsETH interactions as a precaution. The broader DeFi market’s total value locked fell from $26.4 billion to approximately $20 billion over the same period, per DeFi Llama.
rsETH holders on layer 2 networks including Arbitrum, Base, Scroll, Optimism, Mantle, Mode, and Linea face an estimated 15 to 20 percent haircut on their wrapped positions as the bridge reserves backing those tokens are now partially depleted.
Lazarus attribution and what it changes
LayerZero’s attribution to Lazarus Group and the TraderTraitor subunit is preliminary and based on on-chain behavioral patterns, RPC compromise methodology, and wallet movement signatures consistent with prior Lazarus operations. The FBI and Chainalysis have previously documented Lazarus tactics including malicious software planted on infrastructure nodes, the same method used here.
LayerZero said it is working with multiple law enforcement agencies and is actively tracking the stolen funds. Blockchain investigator ZachXBT identified six attacker wallets, and researchers noted funds moved toward mixing services after the drain, complicating recovery.
An analyst quoted by EdaFace News said the realistic best outcome at this point is a 10 to 15 percent white-hat bounty arrangement, in which the attacker returns the bulk of the funds in exchange for keeping a portion and avoiding prosecution — a resolution that has resolved several major DeFi hacks over the past three years, though none of this scale.
Entrepreneur Justin Sun posted publicly to the attacker on social media: “It’s simply not worth it to sacrifice both Aave and KelpDAO and let them go down over this hack.” KelpDAO has not yet issued a detailed post-mortem, saying it is investigating with LayerZero, auditors, and security experts.
What this means for bridge security
The KelpDAO exploit is not the first bridge hack, but it is the first major one directly attributed to a nation-state actor targeting infrastructure rather than contract code. Previous large bridge exploits — Ronin, Wormhole, Nomad — involved bugs in smart contracts or key management failures. This one succeeded by compromising the physical servers validating messages.
The distinction matters for how protocols harden their setups going forward. Multi-signature contract audits will not stop an attacker who owns the machines doing the verification. The solution, security researchers say, is verifier diversity: requiring multiple independent DVNs across different cloud providers, geographies, and software stacks so that compromising any single node — or even two — cannot authorize a fraudulent transaction alone.
LayerZero’s public distancing from KelpDAO’s configuration will likely accelerate pressure on other bridged protocols to audit and upgrade their DVN setups. The question of who bears legal liability when a bridge operator ignores recommended security configurations is now also active in legal circles, particularly given KelpDAO’s apparent failure to follow LayerZero’s integration guidelines.
What is rsETH and why did it lose value?
rsETH is a liquid restaking token issued by KelpDAO, representing staked ETH earning validator rewards. After the exploit minted unbacked rsETH, the token’s collateral ratio broke. Protocols froze it as collateral, creating illiquidity and a price discount for holders trying to exit.
Will Aave cover its losses, and how?
Aave’s automated safety module partially absorbed the shortfall, draining its WETH vault. For the remaining deficit, Aave governance is weighing a proposal to mint new AAVE tokens and sell them to cover the gap — a process that dilutes existing AAVE holders but preserves depositor funds.
Can the stolen funds be recovered?
Recovery is unlikely at full value. Analysts believe the most realistic outcome is a negotiated bounty return where the attacker sends back the majority of funds in exchange for keeping 10 to 15 percent. If Lazarus Group attribution is confirmed, state sanctions complicate any negotiation.








