LayerZero said KelpDAO was hit by a $290 million exploit on April 18, 2026, with rsETH as the only affected asset. The company said the attack abused infrastructure connected to LayerZero through poisoned RPC nodes, while the damage stayed contained to this single application and did not spread to other apps or cross-chain assets.
The exploit targeted verification infrastructure, not protocol code
According to LayerZero, the attacker did not break the protocol itself. The operation focused on external infrastructure used by its Decentralized Verifier Network, or DVN. In practice, the attacker poisoned downstream RPC nodes involved in transaction verification. Two independent RPC nodes were compromised, which let the attacker feed malicious data into the validation path.
That alone was not enough to complete the exploit. LayerZero said the attacker also launched DDoS attacks against healthy RPC nodes, forcing the system to depend on the compromised endpoints. Once that happened, the DVN validated transactions that had never actually taken place.
LayerZero points to tactics associated with Lazarus Group
LayerZero said the attack likely ties back to Lazarus Group, specifically the TraderTraitor unit. The method relied on spoofed RPC responses designed to look normal to monitoring systems. After execution, the malicious setup also removed traces of its activity, making the incident harder to detect and reconstruct.
KelpDAO’s 1-of-1 verifier setup left a single failure point
The breach was confined to rsETH issued by KelpDAO. LayerZero said KelpDAO was running a single-DVN setup at the time, meaning a 1-of-1 verifier model handled all validation. That created a clear single point of failure in the security chain.
LayerZero said it had previously recommended multi-DVN deployments with redundancy across independent verifiers. KelpDAO kept the 1-of-1 configuration. With no extra validation layer in place, the forged message passed through unchecked.
LayerZero replaced affected nodes and dropped support for risky setups
LayerZero stressed that no vulnerability was found in its protocol or core systems, and that the breakdown happened at the application configuration layer. After the incident, the team replaced all affected RPC nodes and restored DVN operations. It also started contacting projects using similar single-verifier designs and said those setups will no longer be supported by its DVN.
LayerZero also said it is coordinating with global law enforcement agencies and working with industry partners to track the stolen funds. The protocol is still reviewing data connected to the exploit.

