LayerZero Labs released an incident report stating that KelpDAO suffered an attack resulting in a loss of approximately $290 million. Preliminary assessments indicate that the attacker is the Lazarus Group, which has ties to North Korea (more specifically, TraderTraitor). The attack was executed by poisoning the downstream RPC infrastructure relied upon by its decentralized verification network (DVN). The attacker controlled some RPC nodes and, in conjunction with a DDoS attack, induced the system to switch to malicious nodes, thereby forging cross-chain transactions.
All affected RPC nodes have been taken offline and replaced, and the DVN has now resumed operation. LayerZero emphasized that this incident was limited to the rsETH application configuration of KelpDAO and did not affect other assets or applications. The reason is that KelpDAO was using a single DVN (1/1) architecture at the time and did not utilize the multi-DVN redundancy mechanism that is officially recommended for long-term use, resulting in a lack of independent verification nodes to identify forged messages.
LayerZero pointed out that there were no vulnerabilities in its protocol itself, and applications with multi-DVN configurations were not affected, meaning there is no contagious risk in the system. LayerZero stated that it will urge all projects using single DVN configurations to migrate to multi-DVN architectures as soon as possible and has suspended providing signature and verification services for 1/1 configuration applications. Meanwhile, the company is cooperating with global law enforcement agencies to investigate and assist industry partners in tracking the stolen funds. LayerZero noted that this incident highlights the value of modular security architecture and also reminds the industry to pay attention to the potential security risks of RPC verification links.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

Key Takeaways An FTX/Alameda-associated wallet moved 4.126 million ZRO tokens to market maker Wintermute, with an approximate value…

Key Takeaways: North Korean operatives have obtained over $500 million from DeFi platforms in under three weeks. The…

Key Takeaways: Total DeFi losses have skyrocketed to approximately $1 billion recently, with $600M+ linked directly to the…

Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…













Key Takeaways: North Korean operatives have obtained over $500 million from DeFi platforms in under three weeks. The…



Key Takeaways: Arbitrum’s security council froze 30,766 ETH connected to a major Kelp exploit, valued at $71.2 million.…

Key Takeaways: The Kelp DAO exploiter has moved $175 million worth of Ether, part of a larger $290…

Key Takeaways: Aave’s total value locked (TVL) plunged from $26.4 billion to $17.94 billion following a massive hack.…








Key Takeaways An FTX/Alameda-associated wallet moved 4.126 million ZRO tokens to market maker Wintermute, with an approximate value…
Key Takeaways: North Korean operatives have obtained over $500 million from DeFi platforms in under three weeks. The…
Key Takeaways: Total DeFi losses have skyrocketed to approximately $1 billion recently, with $600M+ linked directly to the…
Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…