LayerZero Reveals RPC Poisoning Incident Tied to KelpDAO’s $292 Million Hack

LayerZero Reveals RPC Poisoning Incident Tied to KelpDAO’s $292 Million Hack

N
News Editor 01
2026-07-08 21:08:12
LayerZero said its internal RPC infrastructure was poisoned during the KelpDAO breach, which it linked to the Lazarus Group. The firm said the impact was limited but acknowledged critical security design shortcomings and announced major DVN and multisig upgrades.
LayerZeroKelpDAOCross-chain SecurityRPC PoisoningLazarus Group

LayerZero Labs has disclosed that its internal infrastructure was compromised in an RPC poisoning incident linked to the attack on KelpDAO, adding a new layer of detail to one of the more consequential recent security events in cross-chain infrastructure. In an official update, the company said the breach was associated with the Lazarus Group and occurred alongside a distributed denial-of-service attack targeting its external RPC provider. The disclosure came with an apology from the company for remaining largely silent for roughly three weeks while it investigated the matter with outside security partners.

According to LayerZero, the attackers poisoned the source of truth used by internal remote procedure calls that fed its Decentralized Verifier Network, or DVN. In practical terms, the firm said the incident affected a very small part of the broader ecosystem, but it also acknowledged that the attack exposed design and operational weaknesses that should not have existed in systems handling high-value cross-chain transactions.

How LayerZero described the breach

The company said the attack was not a direct failure of the underlying LayerZero protocol itself. Instead, it framed the event as a compromise of supporting infrastructure used by its internal verifier systems. That distinction is important to LayerZero’s defense of its architecture: the protocol argues that its modular design helped contain the impact rather than allowing the breach to become a full ecosystem-wide failure.

LayerZero stated that only one application was affected, representing about 0.14% of all applications connected to the ecosystem and roughly 0.36% of the total value associated with the protocol. Even after April 19, the date from which the company says it has been actively responding to the incident, more than $9 billion in volume moved across the network. The firm also reiterated that cumulative transfers facilitated by LayerZero have exceeded $260 billion to date.

Those figures are being used by the company to show that the damage was contained. At the same time, the incident underscores how attacks on data inputs and verification infrastructure can be just as dangerous as attacks against smart contracts themselves. In cross-chain systems, trust assumptions often extend well beyond onchain code to include validators, data sources, signing flows, and operational defaults.

What LayerZero admitted went wrong

One of the most notable elements of the disclosure was the company’s direct admission that it made a major security mistake. LayerZero said it had allowed its DVN to serve as a solo verifier for high-value transactions. It also conceded that it did not adequately police what its verifier network was securing. In effect, the company recognized that this created a single point of failure, a risk profile fundamentally at odds with the kind of adversaries now targeting major crypto infrastructure.

That admission matters because it points to a broader tension in crypto middleware design: convenience and speed often win out over layered security until a crisis forces a reset. By allowing configurations that concentrated too much trust in one verification path, LayerZero left room for attackers to exploit infrastructure dependencies that should have been more tightly constrained.

The company said it is now working with external security partners to complete a full post-mortem report. While that deeper technical analysis was not included in the initial disclosure, the current update makes clear that LayerZero sees configuration discipline as central to preventing a repeat incident.

DVN changes: no more 1/1 defaults

As part of its response, LayerZero said it will no longer service 1/1 DVN setups, a configuration in which a single verifier path can approve activity. The firm is moving default security toward a 5/5 DVN setup, a more conservative posture intended to reduce the likelihood that one compromised component could affect transaction validation.

The company is also urging developers to pin their own configurations instead of relying on defaults. That recommendation reflects a philosophy LayerZero emphasized in its update: applications should ultimately own their security end to end. The protocol’s role, in this framing, is to provide tools and modular architecture, while developers remain responsible for selecting the trust model that matches the value and risk of their applications.

LayerZero further advised builders to set block confirmation thresholds at levels where chain reorganizations are nearly impossible. That guidance is meant to reduce the risk of finality-related edge cases and improve resilience in environments where attackers may be attempting to exploit timing, state ambiguity, or dependency weaknesses.

Multisig mistakes and the launch of Onesig

The disclosure also included an unusual operational detail involving the company’s multisig practices. LayerZero said that about three and a half years ago, an individual mistakenly used a multisig hardware wallet for a personal trade. Although the incident appears historical, the company included it as part of a broader accounting of security hygiene failures. The signer involved has since been removed.

To improve backend transaction security, LayerZero said it has implemented a custom multisig system called Onesig. The new setup is designed to prevent unauthorized backend transactions by hashing and merklizing transactions locally on the user side before they are signed. The company also plans to increase its multisig threshold from 3/5 to 7/10 on all chains where Onesig is supported.

That move suggests LayerZero is trying to harden not just protocol-level verification, but also internal authorization and governance processes. For a company responding to a threat it attributes to a state-linked adversary, raising signer thresholds and reducing signing ambiguity are sensible defensive steps.

Client diversity, quorum upgrades, and new monitoring tools

Beyond immediate remediation, LayerZero said it is developing a second DVN client written in Rust. Introducing client diversity is a standard security improvement in distributed systems because it reduces the systemic risk of a single software implementation bug or exploit path affecting every verifier running the same codebase.

The company is also upgrading its RPC quorum configuration so DVNs can choose more granular quorums across internal and external providers. In theory, that should make it harder for an attacker to compromise a single source of truth or degrade service in a way that cascades through the verification stack.

Another initiative mentioned in the update is Console, a unified platform for asset issuers to manage security settings and monitor for anomalies. While details remain limited, the product appears intended to give ecosystem participants better visibility into configuration risk and unusual behavior before those issues escalate into losses.

Why the incident matters for cross-chain security

LayerZero’s statement is notable not just because of the numbers involved in the broader KelpDAO incident, but because it highlights the evolving nature of crypto attacks. Sophisticated adversaries are no longer focused only on vulnerabilities in smart contracts. They increasingly target the connective tissue around protocols: RPC infrastructure, verification systems, signers, defaults, and cloud or provider dependencies.

The company’s insistence that the protocol remained operational and that most traffic stayed secure may be technically accurate, but the episode still reinforces a harsh industry lesson. In cross-chain systems, infrastructure compromise can become economically significant even when the base protocol remains intact. Security, in that sense, is only as strong as the weakest operational assumption surrounding the protocol.

The disclosure also arrives as competition in cross-chain messaging and interoperability remains intense. LayerZero itself noted that some DeFi projects have recently chosen to use Chainlink’s CCIP. In that environment, incident transparency and remediation credibility matter not only for security, but also for market trust.

LayerZero’s update ultimately combines apology, technical explanation, and a roadmap for hardening its stack. Whether that is enough to restore confidence will depend on the quality of the forthcoming post-mortem and the speed with which ecosystem participants adopt safer configurations. What is already clear is that the attack has become another case study in how state-linked cyber threats are reshaping the security requirements of crypto infrastructure.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.