Lazarus Suspected of Moving $175M in ETH After Arbitrum Freezes $71M From KelpDAO Hack

Lazarus Suspected of Moving $175M in ETH After Arbitrum Freezes $71M From KelpDAO Hack

N
News Editor 01
2026-07-09 15:39:13
Lazarus Group has been preliminarily linked to the KelpDAO exploit that drained about $292 million in rsETH. While Arbitrum froze roughly $71 million in ETH, onchain tracking suggests another $175 million was moved to fresh Ethereum addresses.
Lazarus GroupKelpDAOArbitrumETHBridge Security

North Korea-linked Lazarus Group has been preliminarily identified as the actor behind the April 18 exploit targeting KelpDAO. According to the reports cited, the attacker withdrew roughly 116,500 rsETH, valued at about $292 million at the time, representing nearly 18% of KelpDAO’s total rsETH supply. In response, the Arbitrum Security Council executed an emergency onchain action on April 20 and froze 30,766 ETH, worth approximately $71 million, tied to the exploiter.

Attack focused on DeFi infrastructure, not end users

The incident appears to have targeted the plumbing of cross-chain DeFi rather than user wallets or front-end interfaces. Reports from KelpDAO, Layerzero, Llamarisk, and Aave-related service providers say the attackers compromised two RPC nodes and used malware to feed false transaction data specifically to Layerzero’s Decentralized Verifier Network while keeping other observers on clean data. They then reportedly launched a distributed denial-of-service attack against the remaining uncompromised nodes, forcing the bridge to fail over to the malicious infrastructure.

With control over the verification layer, the attacker allegedly forged a cross-chain message that authorized the withdrawal of the rsETH. Beyond the funds already frozen, onchain tracking cited in the report indicates Lazarus later moved another $175 million in ETH to new Ethereum addresses. Arkham Intelligence is said to be actively monitoring the wallet activity.

Second major Lazarus-linked exploit in three weeks

The KelpDAO breach is described as the second major exploit attributed to Lazarus within a three-week span. On April 1, Drift Protocol suffered losses of about $285 million in an operation investigators also linked to the same group. Combined, the two incidents bring the damage close to $600 million.

The report places the attack in the broader context of Lazarus’s long-running campaign against the crypto sector. Data referenced in the article says North Korean hackers stole around $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase. Several of the industry’s most severe thefts—including incidents involving Bybit, Ronin Network, DMM Bitcoin, and WazirX—have also been attributed to Lazarus or associated DPRK-linked operations.

Bridge security back under scrutiny

The KelpDAO case once again highlights the structural risks surrounding cross-chain bridges and verification systems. Security researchers cited in the report argue that attackers are increasingly shifting from user-facing exploits toward lower-level infrastructure such as nodes, validators, and message verification pathways. Recommended mitigations include stronger multisignature controls, independent RPC node audits, and real-time behavioral monitoring.

US authorities, including the Treasury Department, the Department of Justice, and the FBI, have previously issued sanctions, indictments, and wallet advisories tied to Lazarus activity. Even so, the group appears to keep evolving its laundering playbook through chain-hopping, DEX swaps, and broad address dispersion, making recovery and enforcement more difficult after each major breach.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.