Layerzero Labs has disclosed that its internal infrastructure was compromised in an RPC poisoning incident linked to the KelpDAO exploit, with the company attributing the operation to North Korea-linked attackers associated with the Lazarus Group. The disclosure adds a significant new layer to the understanding of the KelpDAO breach, which reportedly involved roughly $292 million, and highlights how cross-chain systems remain attractive targets for sophisticated state-backed cyber actors.
In its public update, Layerzero also apologized for remaining largely silent for about three weeks after the incident. The company said it had been working with external security partners since April 19 to complete a more comprehensive post-mortem before speaking in detail. That delay, while intended to support investigation and remediation, became part of the story itself, as Layerzero acknowledged that its communication around the breach response fell short of expectations.
How the Attack Unfolded
According to Layerzero, the attackers poisoned the “source of truth” feeding internal remote procedure calls used by the company’s Decentralized Verifier Network, or DVN. At the same time, the incident coincided with a distributed denial-of-service attack targeting the firm’s external RPC provider. The combination suggests a coordinated attempt to degrade visibility and trust across multiple infrastructure layers rather than exploit a single isolated flaw.
Layerzero described the operation as highly sophisticated. The alleged poisoning of internal RPC data sources is especially notable because RPC endpoints are often treated as operational plumbing rather than the primary battleground in an exploit. In a cross-chain context, however, manipulated data sources can influence verification logic and create downstream security risks if application teams rely too heavily on default trust assumptions.
Contained, but Still Significant
The company said the damage was limited in scope relative to the broader Layerzero ecosystem. By its own figures, the breach affected one application, representing about 0.14% of total applications and roughly 0.36% of the value associated with the protocol. Even though those percentages are small, the event carries outsized importance because it exposed architectural and operational assumptions in a system designed to serve high-value cross-chain activity.
Layerzero stressed that the underlying protocol itself was not directly broken by the RPC poisoning. It argued that the protocol’s modular structure helped isolate the incident and protect the rest of the network. The company noted that more than $9 billion in volume has moved across the network since April 19 without a broader compromise. It also said the architecture has facilitated more than $260 billion in total transfers to date.
Those figures are intended to show resilience, but the incident still underscores a central truth in cross-chain design: localized trust failures can become systemically important if security boundaries are not clearly enforced at the application and verification layers.
Layerzero Admits Configuration and Oversight Failures
One of the most important parts of the disclosure was Layerzero’s admission that it allowed its DVN to operate as a solo verifier for high-value transactions. The company called that a serious oversight. It also conceded that it did not adequately police what its DVN was securing, effectively creating a single point of failure under certain conditions.
That admission matters because it shifts part of the narrative away from an external attacker-only explanation. Layerzero is effectively saying that while the threat actor was sophisticated, some of the risk came from internal security design choices and permissive operational defaults. In other words, the exploit was not only about attacker capability; it also exposed the danger of configurations that concentrate trust too narrowly.
To address this, Layerzero said it will no longer support 1/1 DVN setups. The company is now pushing developers toward safer configurations and plans to migrate defaults to a 5/5 DVN model. It also recommended that developers pin their own configurations instead of relying on defaults and choose block confirmation settings that make chain reorganizations nearly impossible.
Multisig Weaknesses and the Introduction of Onesig
The disclosure also included an unusual operational lapse involving a multisig signer. Layerzero said that around three and a half years ago, an individual mistakenly used a multisig hardware wallet for a personal trade. While the company did not present this as the core cause of the recent exploit, it included the detail as part of a broader effort to disclose historical weaknesses that may have affected security hygiene.
The signer involved has since been removed, according to the company. Layerzero also introduced a custom multisig system called Onesig, which is designed to prevent unauthorized backend transactions by hashing and Merkleizing transactions locally on the user side. The goal is to reduce the risk that backend systems can be abused to create or alter transaction intent outside approved flows.
In parallel, Layerzero said it is raising its multisig threshold from 3/5 to 7/10 on chains where Onesig is supported. That change is part of a broader hardening effort aimed at making the protocol more resistant to advanced adversaries, including state-sponsored groups.
Broader Security Upgrades Ahead
Beyond immediate remediation, Layerzero outlined additional infrastructure upgrades. The team is building a second DVN client in Rust to improve client diversity, an increasingly important best practice in distributed systems where monocultures can magnify technical and security risk. It is also strengthening RPC quorum configurations so DVNs can select more granular quorums across both internal and external providers.
Layerzero further said it is launching Console, a unified platform intended to help asset issuers manage security settings and monitor for anomalous behavior. The introduction of such tooling suggests the company wants security posture to become more visible and configurable for builders, rather than leaving critical trust assumptions buried in infrastructure defaults.
A Warning for the Cross-Chain Sector
The incident is likely to resonate far beyond Layerzero because it reinforces how exposed cross-chain infrastructure remains to well-resourced attackers. Bridges, messaging protocols, verification layers, and oracle-like data pathways continue to sit at the center of crypto’s largest security events. Even when the blast radius is limited, these systems can create concentrated trust dependencies that sophisticated attackers know how to probe.
Layerzero reiterated that its original thesis was that applications should own their security end-to-end in order to avoid systemic risks. The latest disclosure appears to be an effort to realign the ecosystem with that principle by reducing dangerous defaults and encouraging developers to take a more active role in verification and confirmation settings.
The timing is also notable. The report mentioned that some DeFi projects have recently chosen to use Chainlink’s CCIP, underscoring that security design is increasingly becoming a competitive differentiator in the cross-chain market. In an environment where protocol teams are judged not just on speed and interoperability but on the strength of their trust model, incidents like this can shape developer preferences and integration decisions.
Geopolitical Context Remains in the Background
Layerzero’s attribution to actors linked to the Lazarus Group places the event in a broader geopolitical and cybersecurity context. The Lazarus Group has long been accused by governments and security researchers of targeting crypto infrastructure, exchanges, and DeFi systems. Earlier in the week, North Korea’s Foreign Ministry, through state media KCNA, rejected international allegations linking the country to cryptocurrency thefts and cyberattacks, calling them false and politically motivated.
Regardless of the diplomatic denials, Layerzero’s statement reflects the growing normalization of state-linked threats in digital asset infrastructure. For the industry, that means security planning can no longer focus only on ordinary hackers or isolated software bugs. Protocols increasingly need to assume persistent, adaptive, and well-funded adversaries capable of combining social engineering, infrastructure compromise, and coordinated network disruption.
For now, Layerzero is trying to present the incident as both contained and instructive: contained because the protocol says the breach touched only a narrow slice of the ecosystem, and instructive because it exposed exactly where trust assumptions were too weak. Whether the market accepts that framing may depend on the quality of the final post-mortem and how quickly the promised DVN, multisig, and monitoring upgrades are implemented.

