North Korea’s Lazarus Group stole $292 million from Kelp DAO’s cross-chain bridge on April 19, according to a preliminary analysis by LayerZero released the following day — making it the largest decentralized finance exploit of 2026. The attack drained 116,500 rsETH by compromising two RPC nodes and exploiting a single-verifier configuration in LayerZero’s bridge infrastructure, triggering market freezes across 12 protocols and wiping $13.21 billion in total value locked from DeFi within 48 hours.
rsETH is a restaking token — a digital asset representing staked Ethereum deposited into liquid restaking protocols. Because rsETH served as collateral across more than 20 blockchain networks simultaneously, its sudden invalidation put billions in borrowed assets at risk throughout the sector.
Key Takeaways
- Attackers drained 116,500 rsETH ($292 million) from Kelp DAO’s LayerZero-powered bridge on April 19, 2026 — the largest DeFi hack of the year.
- LayerZero attributes the attack to North Korea’s TraderTraitor subunit of Lazarus Group, citing preliminary indicators of a state-sponsored operation.
- Kelp DAO disputes the blame, arguing that the compromised single-verifier setup used LayerZero’s own default infrastructure and documentation.
- Aave faces potential bad debt between $123 million and $230 million; $8.45 billion in deposits fled the protocol within 48 hours of the breach.
Published: April 21, 2026 05:00 UTC
How the attack worked
Attackers pre-staged the operation roughly 10 hours before execution, funding a wallet through Tornado Cash to obscure the origin of funds. At 17:35 UTC on April 19, the attacker compromised two RPC nodes that LayerZero’s bridge verifier relied on to validate cross-chain messages. By simultaneously launching a distributed denial-of-service attack, they forced the system into a failover state — a situation where backup nodes take over during outages. With the verifier disoriented, the attacker submitted a fraudulent message authorizing the transfer of 116,500 rsETH directly to their wallet.
LayerZero’s EndpointV2 contract, which sits at the core of cross-chain communication, approved the forged transaction. The attacker then came within minutes of executing a second drain before Kelp DAO’s engineers detected the breach and halted withdrawals. Analysts noted that the attacker wiped their operational traces during exit, consistent with state-actor tradecraft.
Lazarus attribution and the blame dispute
LayerZero said in a Monday post-mortem that preliminary evidence points to TraderTraitor, a subunit of North Korea’s Lazarus Group responsible for several major crypto thefts in recent years. The firm cited wallet clustering, pre-staging patterns, and on-chain behavior aligned with prior Lazarus operations.
Kelp DAO pushed back the same day. The protocol claims it used LayerZero’s default single-verifier configuration rather than a custom outlier setup, and that LayerZero’s own public documentation and deployment code promote single-source verification. Security researchers at The Block and CoinDesk found that LayerZero’s documentation does not clearly mandate multi-verifier redundancy for bridges holding hundreds of millions in assets, undercutting LayerZero’s claim that Kelp had been repeatedly warned.
LayerZero has said it had repeatedly urged Kelp DAO to adopt multiple verifiers, a safeguard that would have prevented the single-point compromise. The dispute over who bears responsibility for the configuration choice is likely to shape both litigation and future bridge standards across the industry.
DeFi contagion: Aave and beyond
A cross-chain bridge is infrastructure that lets tokens move between separate blockchain networks, often by locking assets on one chain and minting equivalent tokens on another. When Kelp’s bridge was drained, rsETH held as collateral on more than 20 networks lost its backing — creating what Aave’s incident report called “unbacked collateral.”
Borrowers had used that collateral to take out roughly $190 million in loans from Aave, SparkLend, Fluid, and other lending protocols. All three froze rsETH-related markets within hours of the breach. Aave estimates potential bad debt ranging from $123 million to $230 million depending on how liquidations are resolved and whether any stolen funds are recovered.
In the 48 hours following the hack, $8.45 billion in deposits left Aave — a confidence-driven withdrawal spiral rather than a protocol exploit. Total DeFi TVL fell from roughly $29 billion to $15.8 billion, a 45:1 contagion ratio relative to the original $292 million stolen.
What comes next
No funds have been recovered as of April 21. LayerZero has engaged blockchain analytics firms and coordinated with centralized exchanges to flag attacker wallets. On-chain investigators have linked the attacker addresses to wallets previously used in Lazarus-attributed operations, though formal law enforcement action against DPRK-linked actors has historically yielded limited asset recovery.
The incident will likely accelerate two policy responses: bridge security standards and DeFi collateral risk frameworks. The EU’s MiCA regulation does not yet cover DeFi infrastructure, and U.S. lawmakers have signaled upcoming hearings on cross-chain bridge systemic risk following the breach. Aave’s governance forum has opened a discussion thread on collateral quality standards for restaking tokens.
Frequently asked questions
What is a cross-chain bridge and why do hacks keep targeting them?
A cross-chain bridge is software that lets users move tokens from one blockchain to another. Bridges hold large reserves of assets in one place, making them attractive targets. Because they depend on external validators or oracles to confirm transactions, any weakness in that verification layer can be exploited to forge approvals.
Is rsETH still redeemable after the hack?
Kelp DAO has not announced a definitive recovery or compensation plan as of April 21. rsETH trading has continued on secondary markets at a discount to ETH. Protocols that froze rsETH-collateral positions have not yet set timelines for lifting restrictions.
How does Lazarus Group typically move stolen crypto?
The TraderTraitor unit typically converts stolen tokens into ETH or BTC using decentralized exchanges, then moves funds through mixing services like Tornado Cash before bridging to other chains. Chainalysis and TRM Labs have tracked prior Lazarus funds through this pattern over months or years before conversion to fiat.








