On April 18, attackers exploited Kelp DAO's LayerZero-based bridge, stealing 116,500 restaked ETH worth roughly $292 million. The hackers used the seized tokens as collateral on Aave v3 to withdraw wrapped Ether. The incident stands as one of the largest DeFi security breaches this year.
Attack Details and Infrastructure Clash
LayerZero published a post-mortem blaming Kelp DAO for relying on a single validator in its decentralized validator network (DVN). LayerZero stated it had previously cautioned against designs lacking multiple independent checks. Kelp DAO countered that the single-validator (1-1) setup is LayerZero's default configuration and is used by nearly half of all LayerZero users, citing Dune Analytics data. Kelp also claimed LayerZero approved this setup and failed to flag any potential risks.
Escalating Accusations
Kelp DAO noted it had operated on LayerZero's infrastructure since early 2024 with close communication, and the validator arrangement was repeatedly deemed secure. In response, LayerZero announced it will no longer validate cross-chain messages from apps using a single validator and aims to transition such protocols to multi-validator DVN setups. LayerZero co-founder and CEO Bryan Pellegrino posted on social media that “many of Kelp’s claims are simply false,” arguing the default is multi-DVN or DeadDVN and that Kelp manually changed to single-validator mode. He added that independent security firms will soon release full analyses.
Migration and Suspected Perpetrators
“Following the recent LayerZero exploit, we have decided to migrate rsETH to Chainlink CCIP to ensure full security,” Kelp DAO said in a statement on Tuesday. The fund transfer involves $292 million. Meanwhile, attention has turned to North Korea-linked hacking groups, suspected in several major DeFi exploits this year, including a $285 million attack on Drift in early April. The episodes reignite debates over cross-chain bridge security and decentralized validation practices in DeFi.

