
Sophia Bennett
Crypto Analyst
A major security breach has hit the DeFi sector after KelpDAO lost roughly $290 million in a cross‑chain exploit, making it one of the largest crypto hacks of 2026.
The attack targeted KelpDAO’s rsETH product, a liquid restaking token, and was executed through infrastructure connected to LayerZero’s cross‑chain messaging system. The exploit resulted in the draining of approximately 116,500 rsETH, triggering immediate concerns across the broader decentralized finance ecosystem.
Despite the scale of the breach, early assessments indicate that the damage was largely contained to KelpDAO’s specific application, with no widespread contagion across other protocols.
LayerZero Points to KelpDAO’s Configuration
LayerZero, whose technology was used in the exploited bridge, was quick to clarify that the issue did not stem from a flaw in its core protocol.
Instead, the company attributed the exploit to KelpDAO’s use of a “single‑verifier” setup, known as a 1‑of‑1 decentralized verifier network (DVN).
This configuration meant that only one verifier was responsible for confirming transactions. While simpler to operate, it created a single point of failure, a weakness that attackers were able to exploit.
LayerZero noted that it had previously recommended a multi‑verifier setup, which adds redundancy and significantly reduces the risk of such attacks. Without that additional layer of security, the system had no fallback once compromised.
How the Attack Was Carried Out
The exploit itself was highly sophisticated and did not rely on breaking core protocol code or stealing private keys.
Instead, attackers targeted the system’s underlying infrastructure. They:
compromised key RPC (remote procedure call) nodes used for verification
launched a DDoS attack to disrupt legitimate nodes
forced the system to rely on compromised backup nodes
This allowed them to inject false transaction data, effectively validating transfers that never actually occurred.
The result was a large‑scale unauthorized withdrawal of funds from the bridge.
Lazarus Group Suspected Behind the Hack
LayerZero has linked the exploit to North Korea’s Lazarus Group, a state‑backed hacking organization known for targeting crypto platforms.
The group, sometimes referred to as “TraderTraitor”, has been associated with several high‑profile exploits in recent years, often using advanced and multi‑layered attack strategies.
In this case, investigators believe the attack was carefully designed to evade detection, even including mechanisms to erase traces after execution.
Limited Contagion but Industry Concerns Rise
While the exploit was significant, its impact appears contained.
LayerZero confirmed that:
only KelpDAO’s rsETH product was affected
other applications using its protocol remain secure
compromised infrastructure has been replaced and systems restored
However, the incident has still triggered ripple effects across DeFi. Some platforms temporarily restricted exposure to affected assets, and concerns around cross‑chain security have resurfaced.
The Bigger Picture: A Wake‑Up Call for DeFi
The KelpDAO exploit highlights a growing reality in crypto: security risks are no longer just about smart contract bugs.
Instead, attackers are increasingly targeting:
infrastructure layers
network configurations
and operational setups
Even robust protocols can be vulnerable if implemented incorrectly.
The Bottom Line
The $290 million KelpDAO exploit underscores how critical proper system configuration and redundancy are in DeFi.
While LayerZero has distanced its core technology from the breach, the incident shows that even advanced systems can fail if key safeguards are missing.
With the suspected involvement of the Lazarus Group, the attack also reinforces a broader concern, that crypto platforms are facing increasingly sophisticated, state‑linked threats.
For the industry, this may serve as another reminder, “security isn’t just about code, it’s about how everything is put together.”
