BusinessPostCorner.com
No Result
View All Result
Monday, April 20, 2026
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources
BusinessPostCorner.com
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources
No Result
View All Result
BusinessPostCorner.com
No Result
View All Result

LayerZero Says Lazarus Group Likely Behind Kelp DAO Exploit

April 20, 2026
in Crypto News
Reading Time: 6 mins read
A A
0
LayerZero Says Lazarus Group Likely Behind Kelp DAO Exploit
ShareShareShareShareShare

Author

Ahmed Barakat

Author

Ahmed BarakatVerified

Part of the Team Since

Aug 2025

About Author

Ahmed Balaha is a journalist and copywriter based in Georgia with a growing focus on blockchain technology, DeFi, AI, privacy, digital assets, and fintech innovation.

Share


Fact Checked by

CryptoNews Editorial Team

Author

CryptoNews Editorial TeamVerified

Part of the Team Since

Sep 2018

About Author

The CryptoNews editorial team is composed of seasoned writers specializing in cryptocurrency and blockchain technology. Their expertise ensures comprehensive, accurate, and insightful content for…

Last updated: 

April 20, 2026

LayerZero Says Lazarus Group Likely Behind Kelp DAO Exploit

LayerZero has attributed the Kelp DAO exploit to North Korea’s Lazarus Group, identifying a single-point-of-failure in the protocol’s verifier setup as the technical root cause that made the attack possible.

The breach drained an estimated $292 million from Kelp DAO’s rsETH pool on April 18, marking the largest DeFi hack of 2026 to date – and sent total value locked across the DeFi sector down 7% in 24 hours to $85 billion, according to DefiLlama.

LayerZero has attributed the Kelp DAO exploit to North Korea's Lazarus Group, identifying a single-point-of-failure.
DeFi Total Value Locked / Source: DefiLlama

The attribution lands not as a closed finding but as a probabilistic claim: LayerZero says Lazarus is the likely perpetrator, not a confirmed one. What that distinction means for the protocol, its users, and the cross-chain security model is the question this story answers.

Key Takeaways:

  • Attribution source: LayerZero conducted the post-incident investigation and named North Korea’s Lazarus Group – specifically the TraderTraitor subgroup – as the likely perpetrator.
  • Technical root cause: Kelp DAO operated a 1-of-1 DVN (single decentralized verifier node) setup, ignoring LayerZero’s repeated recommendations for multi-verifier redundancy.
  • Exploit amount: Approximately $292 million drained from Kelp DAO’s rsETH pool; no LayerZero protocol code or private keys were compromised.
  • Market impact: DeFi TVL fell 7% in 24 hours to $86 billion following the incident.
  • Response: LayerZero decommissioned affected RPC nodes and restored full DVN operations; law enforcement collaboration is ongoing for fund tracing.
  • Watch: Whether Kelp DAO announces a compensation mechanism and whether additional cross-chain protocols operating single-DVN configurations move to remediate before the next attack.

Discover: The best pre-launch token sales

LayerZero’s Kelp DAO Lazarus Findings: What a Single-Point Failure Actually Means in Cross-Chain Architecture

The exploit’s mechanism was multi-step and precise. Attackers poisoned the RPC infrastructure feeding LayerZero’s decentralized verifier network, then launched a DDoS attack designed to force failover to compromised backup nodes.

With the verifier network redirected, the system validated fictitious cross-chain transactions, and $292 million in rsETH exited Kelp DAO’s pool before the fraud was detected.

Earlier today we identified suspicious cross-chain activity involving rsETH. We have paused rsETH contracts across mainnet and several L2s while we investigate.

We are working with @LayerZero_Core, @unichain, our auditors and top security experts on RCA.

We will keep you…

— Kelp (@KelpDAO) April 18, 2026

The critical enabler: Kelp DAO ran a 1-of-1 DVN configuration, meaning a single verifier node stood between the protocol and catastrophic failure. LayerZero had flagged this architecture as inadequate – multiple times, according to the investigation – and recommended a multi-DVN setup consistent with industry best practices for redundancy. Kelp DAO did not act on those recommendations.

A multi-DVN setup would have required attackers to compromise several independent verification nodes simultaneously, a substantially harder technical lift. The 1-of-1 setup collapsed that barrier entirely. As Ripple CTO David Schwartz put it on X: “The attack was way more sophisticated than I expected and aimed at LayerZero infrastructure taking advantage of KelpDAO laziness.”

LayerZero’s response was surgical: the team decommissioned all affected RPC nodes post-incident and fully restored DVN operations without broader contagion to other protocols using the same infrastructure. No LayerZero protocol code was compromised. No private keys were exposed. The failure was architectural, not foundational – a distinction that matters enormously for the protocol’s credibility but does nothing to recover the $292 million.

Why North Korea Attribution Changes the Threat Model for All of DeFi

LayerZero’s Lazarus Kelp DAO attribution, framed as likely, not confirmed, is consistent with an established and accelerating pattern.

The TraderTraitor subgroup, a known Lazarus operational unit, was preliminarily identified in the forensic analysis. LayerZero is actively collaborating with global law enforcement on fund tracing, suggesting the attribution carries enough evidentiary weight to involve state-level investigative resources.

lazarus stole $7B+ since the beginning of crypto

7 fucking billion

how do you even cash that out?

— nairolf (@0xNairolf) April 20, 2026

Lazarus has been tied to some of the largest crypto thefts on record, including the $625 million Ronin Network hack in 2022 and a string of DeFi protocol exploits that have collectively funneled billions into DPRK’s weapons programs, according to U.S. Treasury and UN assessments.

North Korea’s crypto operations extend well beyond direct exploits – the regime has also embedded operatives inside Web3 companies under fabricated identities, a parallel track that widens the attack surface beyond infrastructure alone.

Cross-chain protocols are structurally attractive targets for this class of actor. They sit at high-value junctions between multiple chains, often carrying pooled liquidity that dwarfs any single application’s balance, and their security depends on verifier networks that can become single points of failure when misconfigured. RPC poisoning as a tactic against verifier networks represents a novel escalation – one that security researchers say is now documented and replicable.

Discover: The best crypto to diversify your portfolio with



Credit: Source link

ShareTweetSendPinShare
Previous Post

XRP Price Prediction: Wrapped XRP Just Launched on Solana — Is This the DeFi Unlock XRP Holders Have Been Waiting For?

Next Post

Michael Saylor Hints at Bigger Bitcoin Buys After Floating Semi-Monthly Dividends

Next Post
Michael Saylor Hints at Bigger Bitcoin Buys After Floating Semi-Monthly Dividends

Michael Saylor Hints at Bigger Bitcoin Buys After Floating Semi-Monthly Dividends

Michael Saylor Hints at Bigger Bitcoin Buys After Floating Semi-Monthly Dividends

Michael Saylor Hints at Bigger Bitcoin Buys After Floating Semi-Monthly Dividends

April 20, 2026
HR isn’t proving that employee engagement delivers ROI

HR isn’t proving that employee engagement delivers ROI

April 14, 2026
The fake images behind AI insurance scams

The fake images behind AI insurance scams

April 17, 2026
Cantor Fitzgerald Donates M to Crypto PAC Led by Tether Exec

Cantor Fitzgerald Donates $10M to Crypto PAC Led by Tether Exec

April 16, 2026
Crisis grants launched for struggling Bradford families

Crisis grants launched for struggling Bradford families

April 15, 2026
XRP Price Prediction: Ripple’s Garlinghouse Expects Clarity Act Next Month

XRP Price Prediction: Ripple’s Garlinghouse Expects Clarity Act Next Month

April 14, 2026
BusinessPostCorner.com

BusinessPostCorner.com is an online news portal that aims to share the latest news about following topics: Accounting, Tax, Business, Finance, Crypto, Management, Human resources and Marketing. Feel free to get in touch with us!

Recent News

‘Tethered to a galaxy far, far away’: former diplomats doubt Trump’s Iran talks can deliver in time

‘Tethered to a galaxy far, far away’: former diplomats doubt Trump’s Iran talks can deliver in time

April 20, 2026
Ineligible businesses getting payroll tax credits

Ineligible businesses getting payroll tax credits

April 20, 2026

Our Newsletter!

Loading
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2023 businesspostcorner.com - All Rights Reserved!

No Result
View All Result
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources

© 2023 businesspostcorner.com - All Rights Reserved!