Full Breakdown
North Korean Hackers Execute $290 Million Heist on KelpDAO
4/22/2026, 8:47:07 PM
Overview of the Attack
On April 18, 2026, North Korean-linked hackers, specifically the Lazarus Group and its TraderTraitor subgroup, executed a sophisticated cyber heist, stealing approximately $290 million in cryptocurrency from KelpDAO, a decentralized finance (DeFi) platform. The breach involved exploiting vulnerabilities in KelpDAO's cross-chain verification process, which is powered by LayerZero, a blockchain interoperability protocol. The attackers siphoned off 116,500 rsETH (restaked ether) through fraudulent transactions, marking this incident as the largest crypto theft of the year.
Mechanism of the Heist
The attack was characterized by a manipulation of KelpDAO's single-verifier setup, which relied on a Decentralized Verifier Network (DVN) that did not require multiple confirmations for transactions. The hackers compromised certain remote procedure call (RPC) nodes and launched a distributed denial-of-service (DDoS) attack on others, forcing the system to rely on the compromised nodes. This allowed them to inject false transaction data that appeared legitimate, facilitating the unauthorized transfer of funds.
LayerZero indicated that the breach was a result of KelpDAO's failure to implement a multi-verifier configuration, which could have mitigated the risk of a single point of failure. "A properly hardened configuration would have required consensus across multiple independent verifiers, rendering this attack ineffective," LayerZero stated.
Impact on the DeFi Ecosystem
The fallout from the KelpDAO breach has been significant, triggering panic across the DeFi sector. Following the incident, over $13 billion was withdrawn from various DeFi platforms, with Aave, a major lending protocol, experiencing a nearly $8 billion drop in total value locked. The stolen funds were reportedly funneled into Aave, where they were used as collateral to borrow additional assets, creating a potential debt of $195 million.
Official Statements & Responses
LayerZero has attributed the attack to the Lazarus Group, emphasizing that the breach was isolated to KelpDAO's infrastructure and did not affect other applications using LayerZero. In contrast, KelpDAO has challenged LayerZero's claims, asserting that its configuration was in line with LayerZero's documentation and that it had maintained open communication with LayerZero regarding security practices.
Criticism & Opposition
Experts have criticized both KelpDAO and LayerZero for their roles in the incident. Security analysts have pointed out that the attack reflects an evolving strategy by North Korean cyber groups, which are increasingly targeting infrastructure vulnerabilities rather than relying solely on traditional hacking methods. The incident has raised concerns about the security of interconnected DeFi systems and the potential for cascading failures across platforms.
Conflicting Reports & Gaps
While LayerZero and KelpDAO have exchanged blame regarding the security configuration, there remains a lack of clarity on the specific vulnerabilities exploited during the attack. Additionally, the total amount of stolen funds and the exact impact on other DeFi protocols are still being assessed, with estimates varying across different reports.
What's Next
As investigations continue, KelpDAO is working with partner organizations to analyze the breach and implement measures to prevent future incidents. The DeFi community is also likely to reassess security protocols in light of this incident, emphasizing the need for robust verification systems to safeguard against similar attacks in the future.
