LayerZero Confirms $290M KelpDAO Exploit Linked to Poisoned RPC Nodes

LayerZero Confirms $290M KelpDAO Exploit Linked to Poisoned RPC Nodes

N
News Editor 01
2026-07-22 17:15:14
LayerZero said the $290 million KelpDAO exploit on April 18, 2026, stemmed from poisoned RPC nodes that distorted DVN verification. The incident was limited to rsETH and did not affect other apps or cross-chain assets.
LayerZeroKelpDAORPC nodessecurity exploitrsETH

LayerZero said KelpDAO was hit by a $290 million exploit on April 18, 2026, with rsETH as the only affected asset. The company said the attack abused infrastructure connected to LayerZero through poisoned RPC nodes, while the damage stayed contained to this single application and did not spread to other apps or cross-chain assets.

The exploit targeted verification infrastructure, not protocol code

According to LayerZero, the attacker did not break the protocol itself. The operation focused on external infrastructure used by its Decentralized Verifier Network, or DVN. In practice, the attacker poisoned downstream RPC nodes involved in transaction verification. Two independent RPC nodes were compromised, which let the attacker feed malicious data into the validation path.

That alone was not enough to complete the exploit. LayerZero said the attacker also launched DDoS attacks against healthy RPC nodes, forcing the system to depend on the compromised endpoints. Once that happened, the DVN validated transactions that had never actually taken place.

LayerZero points to tactics associated with Lazarus Group

LayerZero said the attack likely ties back to Lazarus Group, specifically the TraderTraitor unit. The method relied on spoofed RPC responses designed to look normal to monitoring systems. After execution, the malicious setup also removed traces of its activity, making the incident harder to detect and reconstruct.

KelpDAO’s 1-of-1 verifier setup left a single failure point

The breach was confined to rsETH issued by KelpDAO. LayerZero said KelpDAO was running a single-DVN setup at the time, meaning a 1-of-1 verifier model handled all validation. That created a clear single point of failure in the security chain.

LayerZero said it had previously recommended multi-DVN deployments with redundancy across independent verifiers. KelpDAO kept the 1-of-1 configuration. With no extra validation layer in place, the forged message passed through unchecked.

LayerZero replaced affected nodes and dropped support for risky setups

LayerZero stressed that no vulnerability was found in its protocol or core systems, and that the breakdown happened at the application configuration layer. After the incident, the team replaced all affected RPC nodes and restored DVN operations. It also started contacting projects using similar single-verifier designs and said those setups will no longer be supported by its DVN.

LayerZero also said it is coordinating with global law enforcement agencies and working with industry partners to track the stolen funds. The protocol is still reviewing data connected to the exploit.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.