North Korea-linked Lazarus Group has been preliminarily identified as the actor behind the April 18 exploit targeting KelpDAO. According to the reports cited, the attacker withdrew roughly 116,500 rsETH, valued at about $292 million at the time, representing nearly 18% of KelpDAO’s total rsETH supply. In response, the Arbitrum Security Council executed an emergency onchain action on April 20 and froze 30,766 ETH, worth approximately $71 million, tied to the exploiter.
Attack focused on DeFi infrastructure, not end users
The incident appears to have targeted the plumbing of cross-chain DeFi rather than user wallets or front-end interfaces. Reports from KelpDAO, Layerzero, Llamarisk, and Aave-related service providers say the attackers compromised two RPC nodes and used malware to feed false transaction data specifically to Layerzero’s Decentralized Verifier Network while keeping other observers on clean data. They then reportedly launched a distributed denial-of-service attack against the remaining uncompromised nodes, forcing the bridge to fail over to the malicious infrastructure.
With control over the verification layer, the attacker allegedly forged a cross-chain message that authorized the withdrawal of the rsETH. Beyond the funds already frozen, onchain tracking cited in the report indicates Lazarus later moved another $175 million in ETH to new Ethereum addresses. Arkham Intelligence is said to be actively monitoring the wallet activity.
Second major Lazarus-linked exploit in three weeks
The KelpDAO breach is described as the second major exploit attributed to Lazarus within a three-week span. On April 1, Drift Protocol suffered losses of about $285 million in an operation investigators also linked to the same group. Combined, the two incidents bring the damage close to $600 million.
The report places the attack in the broader context of Lazarus’s long-running campaign against the crypto sector. Data referenced in the article says North Korean hackers stole around $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase. Several of the industry’s most severe thefts—including incidents involving Bybit, Ronin Network, DMM Bitcoin, and WazirX—have also been attributed to Lazarus or associated DPRK-linked operations.
Bridge security back under scrutiny
The KelpDAO case once again highlights the structural risks surrounding cross-chain bridges and verification systems. Security researchers cited in the report argue that attackers are increasingly shifting from user-facing exploits toward lower-level infrastructure such as nodes, validators, and message verification pathways. Recommended mitigations include stronger multisignature controls, independent RPC node audits, and real-time behavioral monitoring.
US authorities, including the Treasury Department, the Department of Justice, and the FBI, have previously issued sanctions, indictments, and wallet advisories tied to Lazarus activity. Even so, the group appears to keep evolving its laundering playbook through chain-hopping, DEX swaps, and broad address dispersion, making recovery and enforcement more difficult after each major breach.

