KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026) — Threadlinqs Intelligence
As of 2026-05-30, KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026) is a critical-severity vulnerability threat attributed to Lazarus Group (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0416 · Severity: CRITICAL · CVSS: 9.6 · Status: MONITORING · Category: VULNERABILITY
Attribution: Lazarus Group · North Korea · FINANCIAL
On April 18, 2026, attackers attributed by Chainalysis to North Korea's Lazarus Group (APT38) drained approximately $292 million (116,500 rsETH) from KelpDAO's LayerZero-based cross-chain bridge. The
THREAT OVERVIEW
On April 18, 2026 at approximately 03:17 UTC, KelpDAO — a liquid restaking protocol built on top of EigenLayer that issues the rsETH liquid restaking token (LRT) — suffered the largest LRT exploit to date. Approximately 116,500 rsETH, valued at roughly $292 million at the time of the exploit, was released on destination chains (Arbitrum, Blast, Base, Mode, and Scroll) through KelpDAO's LayerZero-based cross-chain bridge without a corresponding lock/burn event ever occurring on the Ethereum mainnet source chain.
On-chain analysis published by Chainalysis on April 23, 2026 attributes the operation to the Lazarus Group (tracked as APT38 / TraderTraitor / BlueNoroff / Hidden Cobra), the DPRK-aligned cryptocurrency theft cluster responsible for the Ronin ($625M, 2022), Harmony Horizon ($100M, 2022), Atomic Wallet ($100M, 2023), and Orbit Chain ($81M, 2023) bridge exploits. The attribution is based on wallet clustering with previously sanctioned DPRK-linked addresses, reuse of TraderTraitor social-engineering infrastructure, and overlaps in post-theft laundering patterns through Tornado Cash nova, Railgun, and cross-chain swaps via THORChain and eXch.cx.
ROOT CAUSE — BRIDGE MESSAGE VERIFICATION FAILURE
KelpDAO's cross-chain bridge is built on LayerZero v2's Decentralized Verifier Network (DVN) architecture. In this model, the source-chain endpoint emits a packet when rsETH is burned (locked); one or more DVNs independently attest to the packet hash on the destination chain; and once a configurable quorum of attestations is reached, the Executor delivers the payload to the destination-chain OApp, which triggers the mint/release of rsETH to the recipient.
KelpDAO configured its bridge with a quorum of 2-of-3 DVNs: the LayerZero Labs DVN, Google Cloud DVN, and a Kelp-operated DVN maintained by the KelpDAO bridge engineering team. The root cause of the exploit was operational, not a smart-contract reentrancy or arithmetic bug: Lazarus operators compromised the off-chain signing infrastructure of both the Kelp-operated DVN and a secondary DVN (preliminary reporting points to a compromised LayerZero Labs DVN signer key), giving the attackers the ability to unilaterally satisfy the 2-of-3 quorum for arbitrary message hashes.
With DVN quorum control, the attackers crafted LayerZero packets identical in structure to legitimate burn-attestation packets, but for burn events that never occurred on the Ethereum source chain. The destination-chain rsETH peripheral contract — which trusts the LayerZero Endpoint and its configured DVN set — accepted the forged packets as valid and released rsETH to attacker-controlled addresses on five destination chains.
The vulnerability is not in the LayerZero v2 protocol itself. The flaw is a failure of KelpDAO's DVN governance and operator security model: (1) two of three DVNs were insufficiently segregated (shared personnel and similar access control postures), and (2) no independent on-chain burn-proof requirement (e.g., a source-chain storage proof verified by the destination via a light client) was configured as an additional hard constraint beyond DVN attestation. The exploit is a bridge-layer equivalent of a multisig quorum compromise, similar to Ronin (2022) and Harmony Horizon (2022), rather than a contract bug.
INITIAL ACCESS
Forensic artifacts shared by Mandiant, Chainalysis, and SlowMist indicate that initial access occurred via Lazarus's well-documented TraderTraitor / Operation Dream Job / Contagious Interview playbook. Three KelpDAO bridge engineering personnel and one Google Cloud DVN operator were contacted between March 27, 2026 and April 11, 2026 by fraudulent recruiters impersonating hiring managers from tier-1 DeFi firms on LinkedIn, Telegram, and GitHub. At least two of the targeted engineers were induced to download a purported technical-assessment project from a Lazarus-controlled npm/GitHub repository (RustDoor-style BeaverTail JavaScript stager chained to the I
Weaknesses (CWE)
CWE-345, CWE-347, CWE-287, CWE-306, CWE-20, CWE-1240
Target sectors: decentralized finance, cryptocurrency, liquid staking, liquid restaking, cross-chain infrastructure, financial services
Target regions: Global, North America, Europe, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, T1589, T1589.003, T1593.001, T1585.001, T1587.001, T1588.002, T1583.006, T1566.002, T1566.003, T1195.001