Layerzero Discloses North Korean RPC Poisoning Attack Behind $292M KelpDAO Hack

Layerzero Discloses North Korean RPC Poisoning Attack Behind $292M KelpDAO Hack

N
News Editor 01
2026-07-08 21:10:12
Layerzero Labs revealed that North Korea's Lazarus Group orchestrated an RPC poisoning and DDoS attack on its infrastructure, leading to the $292 million KelpDAO exploit. Only 0.36% of assets were affected; the team deployed enhanced security measures including 5/5 DVN defaults and a new multisig solution.
LayerzeroRPC poisoningKelpDAONorth Korean hackerssecurity incident

Layerzero Labs officially disclosed on Friday, May 9, 2026, that its internal infrastructure was compromised by North Korea's Lazarus Group during the $292 million KelpDAO hack, which was executed through a sophisticated RPC poisoning attack combined with a simultaneous DDoS assault on external RPC providers.

Attack Details: RPC Poisoning and DDoS

According to the post-mortem report, attackers poisoned the source of truth for internal Remote Procedure Calls (RPCs) used by the Layerzero Labs Decentralized Verifier Network (DVN). The attack coincided with a Distributed Denial of Service (DDoS) attack against the firm's external RPC provider, effectively blinding the system. The breach impacted a single application, representing 0.14% of total apps and 0.36% of total value locked (TVL) on the protocol, though the $292 million loss made headlines. Layerzero stressed that the rest of the ecosystem remained secure, with over $9 billion in volume flowing safely through the network since April 19.

Apology and Security Gaps

Layerzero Labs issued a candid apology for a three-week communication blackout following the incident. The team admitted a critical oversight: allowing their DVN to act as a solo verifier (1/1 DVN setup) for high-value transactions, creating a single point of failure. They also failed to monitor what the DVN was securing. To rectify this, Layerzero is migrating all defaults to a 5/5 DVN configuration to eliminate single-validation risk. Developers are being educated on safe configurations, and 1/1 DVN setups will no longer be supported.

Multisig Blunder and the 'Onesig' Solution

The report also detailed a bizarre security lapse involving a multisig signer. Three and a half years ago, an individual mistakenly used a multisig hardware wallet for a personal trade. That signer has been removed. Layerzero subsequently deployed a custom-built multisig solution called “Onesig,” which locally hashes and merklizes transactions to prevent unauthorized backend transactions. Additionally, the team is increasing the multisig threshold from 3/5 to 7/10 across all chains where Onesig is supported, hardening the protocol against state-sponsored threats.

Protocol Recovery and Forward-Looking Upgrades

Despite the breach, Layerzero highlighted that its underlying protocol remained unaffected. The modular architecture ensured that the rest of the $9 billion in recent traffic stayed secure. To prevent future attacks, Layerzero is developing a second DVN client written in Rust for client diversity, implementing a more robust RPC quorum configuration that allows DVNs to select granular quorums across internal and external providers, and launching “Console,” a unified platform for asset issuers to manage security and monitor anomalies. The protocol has facilitated over $260 billion in cumulative transfers to date.

This incident underscores the persistent threat facing cross-chain infrastructure from state-sponsored actors. Earlier this week, North Korea’s Foreign Ministry, via state media KCNA, rejected international accusations linking it to cryptocurrency thefts, calling them “absurd slander” and a politically motivated smear campaign.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.