A cross-chain bridge adapter used by KelpDAO was exploited for approximately $292 million in rsETH on April 18, after attackers found a way to abuse what turned out to be a catastrophically simple weakness: the entire system relied on a single verifier to authenticate transactions.
The breach drained 116,500 rsETH from KelpDAO’s LayerZero-powered Omnichain Fungible Token (OFT) adapter on Ethereum, representing roughly 18% of the token’s circulating supply. The fallout was swift and brutal, with more than $10 billion in withdrawals cascading across DeFi protocols in the hours that followed.
How one validator became a $292M liability
KelpDAO’s bridge adapter was configured with what’s known as a 1-of-1 Decentralized Verifier Network, or DVN. The attackers forged a message claiming that a corresponding burn of rsETH had occurred on Unichain. Because only one validator, operated by LayerZero Labs, needed to sign off on the transaction’s legitimacy, the forged message was all it took. The DVN attested to a transaction that never actually happened, and the Ethereum-side adapter dutifully released the reserves.
The attack vector wasn’t a smart contract bug in the traditional sense. Instead, the attackers compromised LayerZero’s internal RPC nodes, replacing legitimate binaries with counterfeit versions designed to feed fictitious data to the sole DVN. To make sure no backup systems could intervene, they simultaneously launched a DDoS attack against remaining external nodes, forcing the system into a failover state where the compromised nodes became the only source of truth.
KelpDAO’s emergency multisignature team managed to pause the core contracts approximately 46 minutes after the attack began, at around 18:21 UTC. That intervention prevented a follow-up attempt targeting an additional 40,000 rsETH, but the primary damage was already done.
The Lazarus Group connection and partial recovery
Preliminary analysis has linked the attack to North Korea’s Lazarus Group, specifically its TraderTraitor subgroup. The sophistication of the attack, combining supply chain compromise of internal infrastructure with a coordinated DDoS campaign, fits the playbook.
Partial recovery efforts have yielded approximately $71 million so far, roughly a quarter of the stolen funds.
$10 billion in withdrawals and a crisis of confidence
Withdrawals exceeding $10 billion swept across DeFi protocols in the aftermath, with Aave among the platforms that saw notable outflows.
For protocols that currently use LayerZero’s OFT standard, the incident is forcing immediate reassessment of DVN configurations. A 2-of-3 or 3-of-5 DVN setup would have required attackers to simultaneously compromise multiple independent validators, a dramatically harder task.
For investors evaluating DeFi exposure, the lesson is concrete: before parking capital in any protocol that relies on cross-chain messaging, check how many validators stand between your funds and a forged transaction. If the answer is one, you now know exactly how that story ends.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
23









English (US) ·