On April 18, Layerzero Labs published a detailed account on X regarding the ~$290 million exploit of KelpDAO's rsETH. The statement characterized the incident as an infrastructure-level attack, attributing it to a highly-sophisticated state actor, likely DPRK's Lazarus Group (specifically TraderTraitor). According to the firm, the attackers did not breach the Layerzero protocol itself; instead, they poisoned downstream RPC infrastructure used by its Decentralized Verifier Network. By manipulating data fed to verifiers and launching DDoS pressure against uncompromised endpoints, the attackers got fraudulent transactions validated while evading monitoring systems.
Layerzero Labs pinpointed the primary weakness to KelpDAO's rsETH configuration, which relied on a single-DVN structure. Once the supporting infrastructure was compromised, no independent verifier could reject a forged message. The statement argued that a properly diversified multi-DVN setup would have required consensus across multiple verifiers, making the attack ineffective even if one pathway was breached.
Accountability Debate: Protocol Security or User Misconfiguration?
Layerzero Labs emphasized that the impact was contained: “We have conducted a comprehensive review of active integrations … and can confirm with confidence that there is zero contagion to any other asset or application.” The incident was isolated entirely to KelpDAO's rsETH configuration as a direct consequence of their single-DVN setup. Community reception was sharply polarized. Zach Rynes, community liaison at Chainlink, countered on X: “As expected, Layerzero is deflecting responsibility that their own DVN node infrastructure was compromised and caused a $290M bridge exploit.” He argued that the issue stemmed from both infrastructure control and validator concentration, creating a single point of failure—a risk he had flagged years earlier. “Claiming there was no contagion is just the cherry on top,” he concluded. The dispute underscores a deeper divide over accountability when one entity controls both infrastructure and validation.
KelpDAO now faces pressure to adopt multi-DVN setups, signaling tighter security standards ahead. The entire DeFi bridge verification model is under intensified scrutiny.

