LayerZero says North Korea's Lazarus is likely behind the $292M Kelp DAO exploit on April 18, which triggered $10B in outflows from Aave over bad debt concerns
Quick Take — LayerZero said North Korean hacker group Lazarus is likely responsible for the $292 million Kelp DAO exploit.
The BlockDanny Park
Context & Ripple Effects
The incident sits within a broader run of North Korea-linked crypto thefts: related coverage attributes a large share of year-to-date hack losses to the Drift Protocol and Kelp DAO attacks, while the Lazarus name had previously been tied to major bridge thefts.
Follow-up reporting shifts attention from the exploit itself to infrastructure design: LayerZero acknowledged that its single-verifier setup was deficient, and Kelp DAO later reported restoring its restaked Ether token after a five-week recovery effort.
First-order effects
Kelp DAO faces recovery and user-confidence damage after the drain of DAO funds; LayerZero’s attribution places Lazarus at the center of the incident without establishing a final public attribution.
Aave experiences an immediate liquidity shock as users withdraw over fears that exposure could create bad debt.
Second-order effects
LayerZero applications and their users face pressure to review verifier configurations, especially because related coverage found many OApps used the same default setup.
DeFi lenders and liquidity providers are likely to treat cross-protocol exposure more cautiously, making a security failure in one protocol capable of transmitting stress to adjacent lending markets.
Third-order effects
If repeated, this pattern makes verifier and bridge-security design a system-level DeFi risk rather than an isolated application issue, because losses can quickly become collateral and liquidity concerns elsewhere.
The recurrence of large Lazarus-linked incidents reinforces the crypto legitimacy gap: recovery processes and security assurances become central to whether users view decentralized financial infrastructure as dependable.
The trend: Cross-chain and restaking infrastructure is becoming a concentrated source of DeFi contagion risk, where security assumptions can matter as much as a protocol’s own balance sheet.
such elaborate distancing doesn't sit well with me. it literally says “the protocol functioned exactly as intended”. the attack is described as a compromise of an rpc node and rpc poisoning. but that's not what rpc poisoning means, their own infra was breached and compromised.
key takeaway from the article: the LayerZero protocol, *when used as intended*, is not safe. i'd add, the protocol is certainly safe when it is intended not to use it in the first place [image]
the kelp rsETH post-mortem is wild lazarus (dprk) compromised two rpc nodes that layerzero dvn was relying on. swapped the op-geth binaries. wrote a custom payload that forged messages *only when the dvn queried* - every other IP, including monitoring, saw clean truthful data. [i…
TL:DR: * LayerZero says it was Kelp's fault for running 1/1 DVN setup, their docs warn against that (although LZ operated the actual DVN) * Yep, North Korea again * LayerZero had solid opsec but still got pwned (they're not disclosing the original compromise path it seems) *
The attack was 1. North Korea figured out which RPC providers LZ was using 2. They compromised two of the providers to make them return fake data 3. DDoSed other providers to shut them down, forcing LZ to use the bad ones AFAIK I was the only one who actually called it [image]
As expected, LayerZero is deflecting responsibility that their own DVN node infrastructure was compromised and caused a $290M bridge exploit They throw KelpDAO under the bus for the crime of trusting the LayerZero Labs DVN, a 1/1 setup they willingly supported and only blocked