Kelp DAO LayerZero Bridge Exploit event
Overview
On 18 April 2026, an exploit of Kelp DAO’s rsETH bridge, built on LayerZero, drained approximately $292 million, or 116,500 rsETH. The incident became the largest crypto theft of 2026 at that point. The breach did not stem from a smart contract flaw; instead, attackers tied to North Korea’s Lazarus Group used social engineering against a LayerZero Labs developer in March 2026. They obtained session keys, infiltrated LayerZero’s RPC cloud environment, poisoned internal RPC nodes, and incorporated a distributed denial-of-service element. LayerZero initially attributed the loss to Kelp’s use of a 1-of-1 decentralized verifier network configuration. Kelp countered that LayerZero’s default templates had recommended that setup. LayerZero later conceded that it had ‘made a mistake.’ Following the event, Kelp announced it would migrate rsETH messaging to Chainlink CCIP.
Relations
No connections recorded for this entity in The Counterparty knowledge graph yet.
Frequently asked questions
What is Kelp DAO LayerZero Bridge Exploit?
Kelp DAO LayerZero Bridge Exploit is a security-exploit tracked in The Counterparty knowledge graph.
What type of entity is Kelp DAO LayerZero Bridge Exploit?
Kelp DAO LayerZero Bridge Exploit is classified as a security-exploit (event) in The Counterparty knowledge graph.
Sources
Facts in this record were checked against the following. Where a claim is not covered here, the record states only what the graph holds.