Lazarus Group blamed for $292M Kelp DAO bridge hack

Kelp DAO Lazarus Group DeFi bridge hack exploit

North Korea’s Lazarus Group carried out the $292 million Kelp DAO bridge exploit on April 18, according to LayerZero, which published its preliminary attribution Monday morning. The attack drained 116,500 rsETH — roughly 18% of the token’s circulating supply — in under an hour, triggering emergency freezes across nine DeFi protocols and a $13.21 billion collapse in total value locked over 48 hours.

Restaked ether (rsETH) is a liquid token issued by Kelp DAO that represents ETH deposited into EigenLayer, Ethereum’s restaking protocol, which allows users to earn additional staking rewards by reusing their staked ETH as security for other networks.

Key Takeaways

  • Kelp DAO lost 116,500 rsETH ($292 million) on April 18 when attackers exploited its LayerZero-powered bridge by poisoning RPC nodes used to verify cross-chain messages.
  • LayerZero today attributed the attack to Lazarus Group’s TraderTraitor subunit and blamed Kelp for ignoring prior advice to use a multi-verifier configuration.
  • Aave, the largest DeFi lending platform, absorbed roughly $196 million in bad debt after attackers used stolen rsETH as collateral to borrow wrapped ether before markets were frozen.
  • Total DeFi value locked has fallen $13.21 billion in 48 hours; Lazarus Group has now drained over $575 million from the sector in just 18 days.

Published: April 20, 2026 08:30 UTC

How attackers bypassed LayerZero’s verification

LayerZero’s EndpointV2 contract is the mechanism that verifies cross-chain messages before releasing bridge funds. Kelp’s bridge relied on LayerZero’s decentralized verified network (DVN) — a set of independent node operators that cross-check messages to confirm they are legitimate before assets move between chains.

A decentralized verified network (DVN) is a group of independent node operators that cross-check messages sent between blockchains to prevent fraudulent transactions from triggering fund releases.

Lazarus Group’s TraderTraitor subunit obtained the list of RPC nodes used by Kelp’s DVN configuration. They poisoned two of those nodes to deliver a fabricated cross-chain instruction, then launched a coordinated DDoS attack against the remaining clean nodes, forcing the DVN to rely exclusively on the compromised ones. The fake message passed verification. Kelp’s bridge released 116,500 rsETH to an attacker-controlled address at 17:35 UTC on April 18, per on-chain data from CoinDesk.

LayerZero’s post-incident statement is pointed: Kelp used a single-verifier setup despite repeated warnings from LayerZero to adopt a multi-verifier configuration. In that setup, one compromised DVN was sufficient to approve any fraudulent transaction.

Contagion spreads across nine protocols

After draining the bridge, attackers moved fast. They deposited the stolen rsETH into Aave V3 on Ethereum and Arbitrum as collateral, then borrowed wrapped ether against it — before the broader market recognized that rsETH was now effectively unbacked.

Aave froze its rsETH markets on both V3 and V4 within hours, but the damage was done. The protocol was left with roughly $196 million in bad debt concentrated in the rsETH/wrapped ether pool on Ethereum, according to The Defiant. Aave’s total value locked dropped $6.6 billion and the AAVE token fell 16%.

Compound, Fluid, SparkLend, Upshift, and Euler all followed with their own emergency rsETH freezes. Across DeFi, total value locked dropped from roughly $110 billion to $96.79 billion in 48 hours — a $13.21 billion decline tracked by DeFi Llama.

Aave’s Umbrella reserve, designed as a backstop for extreme stress events, may not fully cover the $196 million deficit. If it falls short, stkAAVE holders could absorb the remaining losses — a scenario Aave’s community is now debating through an emergency governance vote.

Lazarus Group’s 18-day, $575 million run through DeFi

Today’s LayerZero attribution connects the Kelp exploit to the same Lazarus Group subunit that drained Drift Protocol on April 1 through social engineering of governance signers — a structurally different attack that netted roughly $283 million. Combined, North Korea’s state-sponsored hackers have extracted more than $575 million from DeFi in 18 days using two entirely different methods.

Lazarus Group is the United States Treasury’s Office of Foreign Assets Control (OFAC)-sanctioned hacking unit attributed to the North Korean government, linked to an estimated $3 billion in crypto thefts between 2017 and 2023 by United Nations investigators. Recovery of funds from state actors is rare. A crypto billionaire reportedly reached out to the suspected attacker directly to propose informal negotiations, per Benzinga, though such approaches have historically produced no results in Lazarus-linked incidents.

What comes next for Kelp, LayerZero, and Aave

Kelp DAO had not published a full post-mortem as of Monday morning. The team faces pressure to address how, if at all, impacted users will be compensated for the rsETH shortfall — with 116,500 tokens effectively missing from the protocol’s reserves.

LayerZero is under industry pressure to clarify whether it will enforce minimum security standards, including mandatory multi-verifier configurations, for protocols using its infrastructure. The Kelp breach joins a growing pattern: Web3 security firm Hacken reported that Web3 hacks totaled $482 million in Q1 2026 alone. The Kelp exploit now represents over 60% of that quarterly total in a single weekend.

For DeFi users, the incident is a reminder that interconnected lending markets amplify the blast radius of any bridge failure. Kelp’s bridge held $292 million; Aave’s bad debt reached $196 million from a protocol that was not itself compromised.

Frequently Asked Questions

What is Kelp DAO and what does it do?

Kelp DAO is a liquid restaking protocol built on EigenLayer, Ethereum’s restaking layer. It lets users deposit ETH and receive rsETH, a tradeable token representing their restaked position, which can be used across DeFi protocols for additional yield. The protocol held over $1.6 billion in assets before the exploit.

How did attackers use Aave to amplify the damage?

After stealing rsETH from Kelp’s bridge, attackers deposited the tokens into Aave’s lending markets as collateral and borrowed wrapped ether against them. Aave’s price feeds initially treated the rsETH as legitimate, allowing the loans to go through. When Aave froze the markets, the rsETH collateral was worthless, leaving roughly $196 million in bad debt.

Are Aave users with other positions at risk?

Aave has frozen its rsETH markets and isolated the bad debt to the rsETH/wrapped ether pools. Users in other Aave markets are not directly exposed to the Kelp shortfall, though Aave’s governance vote on bad debt recovery may affect stkAAVE holders if the Umbrella reserve falls short of covering the full $196 million deficit.

Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *