Layerzero Labs officially disclosed on Friday, May 9, 2026, that its internal infrastructure was compromised by North Korea's Lazarus Group during the $292 million KelpDAO hack, which was executed through a sophisticated RPC poisoning attack combined with a simultaneous DDoS assault on external RPC providers.
Attack Details: RPC Poisoning and DDoS
According to the post-mortem report, attackers poisoned the source of truth for internal Remote Procedure Calls (RPCs) used by the Layerzero Labs Decentralized Verifier Network (DVN). The attack coincided with a Distributed Denial of Service (DDoS) attack against the firm's external RPC provider, effectively blinding the system. The breach impacted a single application, representing 0.14% of total apps and 0.36% of total value locked (TVL) on the protocol, though the $292 million loss made headlines. Layerzero stressed that the rest of the ecosystem remained secure, with over $9 billion in volume flowing safely through the network since April 19.
Apology and Security Gaps
Layerzero Labs issued a candid apology for a three-week communication blackout following the incident. The team admitted a critical oversight: allowing their DVN to act as a solo verifier (1/1 DVN setup) for high-value transactions, creating a single point of failure. They also failed to monitor what the DVN was securing. To rectify this, Layerzero is migrating all defaults to a 5/5 DVN configuration to eliminate single-validation risk. Developers are being educated on safe configurations, and 1/1 DVN setups will no longer be supported.
Multisig Blunder and the 'Onesig' Solution
The report also detailed a bizarre security lapse involving a multisig signer. Three and a half years ago, an individual mistakenly used a multisig hardware wallet for a personal trade. That signer has been removed. Layerzero subsequently deployed a custom-built multisig solution called “Onesig,” which locally hashes and merklizes transactions to prevent unauthorized backend transactions. Additionally, the team is increasing the multisig threshold from 3/5 to 7/10 across all chains where Onesig is supported, hardening the protocol against state-sponsored threats.
Protocol Recovery and Forward-Looking Upgrades
Despite the breach, Layerzero highlighted that its underlying protocol remained unaffected. The modular architecture ensured that the rest of the $9 billion in recent traffic stayed secure. To prevent future attacks, Layerzero is developing a second DVN client written in Rust for client diversity, implementing a more robust RPC quorum configuration that allows DVNs to select granular quorums across internal and external providers, and launching “Console,” a unified platform for asset issuers to manage security and monitor anomalies. The protocol has facilitated over $260 billion in cumulative transfers to date.
This incident underscores the persistent threat facing cross-chain infrastructure from state-sponsored actors. Earlier this week, North Korea’s Foreign Ministry, via state media KCNA, rejected international accusations linking it to cryptocurrency thefts, calling them “absurd slander” and a politically motivated smear campaign.

