An attacker targeting Kelp DAO's LayerZero-powered cross-chain bridge, appears to have drained ~$292M worth of rsETH before Kelp paused all rsETH contracts
Quick Take — An attacker seemingly drained 116,500 rsETH from Kelp DAO's LayerZero-powered cross-chain bridge on Saturday …
Context & Ripple Effects
This incident became a test of the security assumptions behind LayerZero-connected applications, not just Kelp DAO’s recovery process. Follow-on coverage tied the exploit to suspected Lazarus activity, reported large Aave outflows over bad-debt fears, and later documented LayerZero’s admission that a single-verifier configuration was deficient.
The subsequent restoration of Kelp’s restaked Ether token after a five-week recovery limits the immediate endpoint to a permanent loss narrative, but it does not remove the configuration and trust-model questions raised for other LayerZero OApps. Dune data cited in later coverage indicated that the same default setup was widely used at the time.
First-order effects
- Kelp DAO’s pause of all rsETH contracts halts normal token operations while it contains the apparent bridge drain, directly disrupting rsETH holders and integrations dependent on transfers or contract interactions.
- LayerZero’s role in the bridge puts its verification configuration and incident response under immediate scrutiny alongside Kelp DAO’s own controls.
Second-order effects
- Protocols and users exposed to rsETH or related collateral can reassess counterparty and bad-debt risk; the reported Aave outflows show how a bridge incident can quickly transmit concern into lending liquidity.
- Other LayerZero OApps using the default single-verifier setup face pressure to review or replace that configuration, particularly after LayerZero characterized it as deficient.
Third-order effects
- If cross-chain applications continue to rely on concentrated verification paths, bridge risk will be priced as a shared infrastructure dependency rather than an isolated protocol failure.
- The episode favors more explicit disclosure of verifier arrangements, fail-safe controls, and recovery procedures, though whether that becomes a durable standard depends on adoption across bridge-connected protocols.
The trend: This is one instance of cross-chain infrastructure risk being re-evaluated through the security design and operational resilience of the verification layer, not only the protocol that is exploited.