A massive cross-chain security breach has intensified scrutiny of DeFi bridge design, after LayerZero Labs released a statement on April 18 detailing the approximately $290 million exploit of KelpDAO's rsETH liquid restaking token. The company framed the incident as an infrastructure-level attack by a highly sophisticated state actor, likely the DPRK's Lazarus Group (TraderTraitor).
LayerZero's Account: Isolated Infrastructure Attack, Zero Contagion
According to LayerZero Labs, the attackers did not exploit the protocol itself, but rather poisoned the downstream remote procedure call (RPC) infrastructure used by its Decentralized Verifier Network (DVN). They manipulated the data presented to the verifier and launched DDoS attacks against uncompromised endpoints, enabling fraudulent transactions to pass validation while avoiding detection across monitoring systems.
The statement emphasized that the primary weakness was KelpDAO's one-of-one DVN configuration, which left no independent verifier capable of rejecting a forged message once the supporting infrastructure was compromised. LayerZero Labs argued that a properly diversified multi-DVN setup would have required consensus across multiple verifiers, rendering the attack ineffective. They also confirmed: “We have conducted a comprehensive review of active integrations... and we can confirm with confidence that there is zero contagion to any other asset or application,” adding that the incident was “isolated entirely to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup.”
Community Pushback and the Centralization Debate
The response from the crypto community was sharply divided. Zach Rynes, community liaison at Chainlink, directly challenged LayerZero's narrative. He posted on X: “As expected, Layerzero is deflecting responsibility that their own DVN node infrastructure was compromised and caused a $290M bridge exploit.” He argued that the issue stemmed from both infrastructure control and validator concentration, creating a single point of failure. Rynes noted he had flagged this centralization risk years earlier, warning that such setups expose users to outsized systemic risk. “Claiming there was no contagion is just the cherry on top,” he concluded.
This dispute reflects a broader divide over accountability when one entity controls both infrastructure and validation. KelpDAO now faces pressure to adopt multi-DVN configurations, signaling tighter security standards ahead. The event underscores the structural vulnerabilities in DeFi bridge security models and will likely drive industry-wide discussions on balancing decentralization and efficiency in verifier design.

