Kelp DAO Loses $292 Million in rsETH Bridge Attack, Plans Chainlink Migration

Kelp DAO Loses $292 Million in rsETH Bridge Attack, Plans Chainlink Migration

N
News Editor 01
2026-07-22 21:10:14
Kelp DAO said its rsETH bridge attack led to about $292 million in losses. The dispute with LayerZero centers on validator configuration, while Kelp DAO says it will move the bridge to Chainlink’s cross-chain protocol.
Kelp DAOLayerZerorsETHcross-chain bridgeChainlink

Kelp DAO said its Ethereum-based rsETH bridge was exploited on April 16, with attackers withdrawing 116,500 rsETH in an incident valued at about $292 million. The report says the hackers are believed to be linked to North Korea’s Lazarus Group. In the aftermath, Kelp DAO and LayerZero have clashed over validator design and responsibility for the breach.

Attack route centered on validator infrastructure

According to the published account, the attackers first compromised two RPC servers inside the LayerZero Labs validator network and installed malicious software. They then launched a DDoS attack against the remaining nodes, which redirected protocol activity to fake nodes. LayerZero said that this chain of events led the system to approve transactions that never actually took place. Beyond the initial rsETH withdrawal, the breach also involved two additional fraudulent transactions worth more than $100 million each.

After the exploit, LayerZero said the protocol had functioned “exactly as designed” and added that applications using the one-to-one validator model would no longer be eligible to sign. Kelp DAO pushed back with newly released documentation. It said the LayerZero team had reviewed Kelp’s one-to-one validator setup over two and a half years across eight separate integration meetings without raising security objections. Shared screenshots also suggest the validator setup decision was left to Kelp and that moving to a private validator was not presented as mandatory. The article notes, though, that it is still unclear whether those messages were independently verified.

Nearly half of LayerZero OApps used similar setup

Kelp DAO also pointed to LayerZero’s official bug bounty terms, which explicitly exclude application-side misconfigurations from eligibility. It added that most official examples use the single-validator, or DVN, model. Data cited from Dune Analytics shows that within the past 90 days, nearly 47% of about 2,665 LayerZero OApp contracts were configured with one-to-one validators, putting roughly $4.5 billion in assets at comparable risk.

In its statement, Kelp DAO said the security issue was not detected by LayerZero and was instead identified by Kelp itself, raising questions about LayerZero’s monitoring systems. The statement also alleged significant administrator overlap between two separate validator networks. On several blockchains, the LayerZero Labs validator network still serves as the only authority.

rsETH bridge set to move off LayerZero

Following the breach, Kelp DAO said it will migrate the rsETH bridge away from LayerZero infrastructure and onto Chainlink’s cross-chain protocol. Under that plan, rsETH would fully adopt Chainlink’s architecture and phase out LayerZero standards. The article says the size of the exploit and the dispute that followed have echoed across the crypto sector. As of the source report, LayerZero officials had not issued any new public statement on the matter.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.