KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026)

KelpDAO LayerZero Bridge Exploit (TL-2026-0416), also tracked as KelpDAO Bridge Hack, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-04-23. It is attributed to Lazarus Group (North Korea) with high confidence, affects KelpDAO rsETH Cross-Chain Bridge (LayerZero OApp), maps to 29 MITRE ATT&CK techniques (T1005, T1036.005, T1041), and is covered by 9 detection rules and 32 indicators of compromise.

Key facts for TL-2026-0416

Threat ID
TL-2026-0416
Also known as
KelpDAO Bridge Hack, rsETH Bridge Exploit, Operation Kelp Harvest, April 2026 LayerZero DVN Compromise
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
2026-04-23
Last reviewed
2026-04-23
Attribution
Lazarus Group
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
decentralized finance, cryptocurrency, liquid staking, liquid restaking, cross-chain infrastructure, financial services
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
32

Malware and tooling in KelpDAO LayerZero Bridge Exploit

Malware and tooling: BeaverTail - S1246, InvisibleFerret - S1245, KANDYKORN, RustDoor, Cloudflare Workers / Pages domain fronting for BeaverTail-InvisibleFerret C2, Railgun, THORChain, Tornado Cash Nova (Gnosis deployment), eXch.cx

On April 18, 2026, attackers attributed by Chainalysis to North Korea's Lazarus Group (APT38) drained approximately $292 million (116,500 rsETH) from KelpDAO's LayerZero-based cross-chain bridge. The attackers compromised a quorum of the KelpDAO bridge's Decentralized Verifier Network (DVN) operators via Lazarus's signature TraderTraitor-style recruiter spearphishing, then submitted forged LayerZero messages to the destination-chain rsETH bridge peripheral, causing rsETH to be minted/released against burn events that never occurred on Ethereum mainnet. It is the single largest liquid restaking token (LRT) exploit recorded and the largest cross-chain bridge incident of 2026.

How KelpDAO LayerZero Bridge Exploit works

THREAT OVERVIEW

On April 18, 2026 at approximately 03:17 UTC, KelpDAO — a liquid restaking protocol built on top of EigenLayer that issues the rsETH liquid restaking token (LRT) — suffered the largest LRT exploit to date. Approximately 116,500 rsETH, valued at roughly $292 million at the time of the exploit, was released on destination chains (Arbitrum, Blast, Base, Mode, and Scroll) through KelpDAO's LayerZero-based cross-chain bridge without a corresponding lock/burn event ever occurring on the Ethereum mainnet source chain.

On-chain analysis published by Chainalysis on April 23, 2026 attributes the operation to the Lazarus Group (tracked as APT38 / TraderTraitor / BlueNoroff / Hidden Cobra), the DPRK-aligned cryptocurrency theft cluster responsible for the Ronin ($625M, 2022), Harmony Horizon ($100M, 2022), Atomic Wallet ($100M, 2023), and Orbit Chain ($81M, 2023) bridge exploits. The attribution is based on wallet clustering with previously sanctioned DPRK-linked addresses, reuse of TraderTraitor social-engineering infrastructure, and overlaps in post-theft laundering patterns through Tornado Cash nova, Railgun, and cross-chain swaps via THORChain and eXch.cx.

ROOT CAUSE — BRIDGE MESSAGE VERIFICATION FAILURE

KelpDAO's cross-chain bridge is built on LayerZero v2's Decentralized Verifier Network (DVN) architecture. In this model, the source-chain endpoint emits a packet when rsETH is burned (locked); one or more DVNs independently attest to the packet hash on the destination chain; and once a configurable quorum of attestations is reached, the Executor delivers the payload to the destination-chain OApp, which triggers the mint/release of rsETH to the recipient.

KelpDAO configured its bridge with a quorum of 2-of-3 DVNs: the LayerZero Labs DVN, Google Cloud DVN, and a Kelp-operated DVN maintained by the KelpDAO bridge engineering team. The root cause of the exploit was operational, not a smart-contract reentrancy or arithmetic bug: Lazarus operators compromised the off-chain signing infrastructure of both the Kelp-operated DVN and a secondary DVN (preliminary reporting points to a compromised LayerZero Labs DVN signer key), giving the attackers the ability to unilaterally satisfy the 2-of-3 quorum for arbitrary message hashes.

With DVN quorum control, the attackers crafted LayerZero packets identical in structure to legitimate burn-attestation packets, but for burn events that never occurred on the Ethereum source chain. The destination-chain rsETH peripheral contract — which trusts the LayerZero Endpoint and its configured DVN set — accepted the forged packets as valid and released rsETH to attacker-controlled addresses on five destination chains.

The vulnerability is not in the LayerZero v2 protocol itself. The flaw is a failure of KelpDAO's DVN governance and operator security model: (1) two of three DVNs were insufficiently segregated (shared personnel and similar access control postures), and (2) no independent on-chain burn-proof requirement (e.g., a source-chain storage proof verified by the destination via a light client) was configured as an additional hard constraint beyond DVN attestation. The exploit is a bridge-layer equivalent of a multisig quorum compromise, similar to Ronin (2022) and Harmony Horizon (2022), rather than a contract bug.

INITIAL ACCESS

Forensic artifacts shared by Mandiant, Chainalysis, and SlowMist indicate that initial access occurred via Lazarus's well-documented TraderTraitor / Operation Dream Job / Contagious Interview playbook. Three KelpDAO bridge engineering personnel and one Google Cloud DVN operator were contacted between March 27, 2026 and April 11, 2026 by fraudulent recruiters impersonating hiring managers from tier-1 DeFi firms on LinkedIn, Telegram, and GitHub. At least two of the targeted engineers were induced to download a purported technical-assessment project from a Lazarus-controlled npm/GitHub repository (RustDoor-style BeaverTail JavaScript stager chained to the InvisibleFerret Python backdoor, with macOS variants dropping the KandyKorn/BlueNoroff ObjectiveSee-detected post-exploit implant).

The implant established C2 over WebSocket to Cloudflare Workers-fronted infrastructure and exfiltrated 1Password vault session tokens, AWS IAM keys, and — critically — DVN signing keys held in HashiCorp Vault instances accessible from the engineers' workstations. Lazarus has used essentially identical initial-access tradecraft in Axie Infinity / Ronin (2022), CoinsPaid (2023), Alphapo (2023), Stake.com (2023), CoinBerry staff phishing (2023), and Radiant Capital operator compromise (October 2024).

EXPLOIT EXECUTION

Between April 15 and April 17, 2026, the attackers performed low-value test transactions (0.01 rsETH and smaller) on each of the five destination chains to confirm that their forged DVN attestations would be accepted by the destination OApp. At 03:17 UTC on April 18, 2026, a coordinated burst of forged LayerZero packets was submitted: 116,500 rsETH was released across 38 transactions over a 42-minute window.

The attackers immediately unstaked rsETH into ETH via KelpDAO's native unstaking queue where possible; sold rsETH for ETH, USDC, and USDT via KyberSwap, Uniswap v4, and 1inch aggregators on each destination chain; bridged a portion of proceeds back to Ethereum mainnet via alternative bridges (Across, Stargate's non-KelpDAO path, and Orbiter); and began laundering via Tornado Cash nova (on Gnosis), Railgun, and THORChain swaps to BTC and TRON USDT within 8 hours of the initial theft.

IMPACT

116,500 rsETH released without corresponding burn; approximately $292M USD equivalent at time of exploit. rsETH de-pegged from ETH by approximately 7.4% within the first hour; recovered to a 2.1% discount after KelpDAO announced socialized-loss treasury backstop. KelpDAO TVL fell from $2.8B to $1.9B within 24 hours as depositors withdrew. Downstream impact on EigenLayer restaking economy and on protocols integrating rsETH as collateral (Pendle, Morpho Blue, Gearbox, Silo Finance) with temporary freezes on rsETH markets pending peg stabilization.

ATTRIBUTION EVIDENCE

(1) Wallet clustering: primary exfiltration wallets share counterparty graphs with OFAC-sanctioned addresses from the Ronin, Harmony Horizon, and Atomic Wallet incidents. (2) TraderTraitor infrastructure reuse: recruiter personas on LinkedIn overlap with personas previously used against Radiant Capital (October 2024) and Munchables (March 2024). (3) Malware family: the BeaverTail/InvisibleFerret/KandyKorn chain is exclusively observed in DPRK-aligned operations. (4) Laundering path: use of Tornado Cash nova on Gnosis, THORChain, and eXch.cx matches the documented post-Stake.com and post-CoinsPaid laundering methodology. (5) Timing: theft occurred during DPRK business hours (Pyongyang Standard Time).

REMEDIATION AND DEFENSIVE LESSONS

KelpDAO has announced: pausing of all LayerZero-based rsETH bridging; rotation of all DVN signing keys; migration to a 3-of-5 DVN configuration adding Polyhedra zkLightClient and Nethermind DVNs with strict personnel segregation; introduction of an on-chain source-chain burn proof via Polyhedra zkBridge as a mandatory co-verifier on the destination side. The broader LayerZero ecosystem is reviewing DVN operator due-diligence requirements, with several protocols (Stargate, Radiant, Angle) publishing revised DVN configurations as of April 22, 2026. Defenders operating LayerZero-based OApps should: audit DVN set composition for true personnel/infrastructure independence; enforce a zk or light-client-based source-chain proof in addition to DVN attestation for high-value assets; implement per-message and per-window value caps at the OApp layer; monitor for anomalous packet volume or value spikes; and treat DVN operators as high-value targets with dedicated anti-phishing and key-custody controls (HSM, multi-party computation).

MITRE ATT&CK techniques used in TL-2026-0416

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication

Persistence

T1078.004 Valid Accounts: Cloud Accounts

Initial Access

T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service

Credential Access

T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys; T1555.005 Password Managers

Lateral Movement

T1550.001 Use Alternate Authentication Material: Application Access Token

Discovery

T1580 Cloud Infrastructure Discovery

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1585.001 Establish Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1589 Gather Victim Identity Information; T1589.003 Gather Victim Identity Information: Employee Names; T1593.001 Search Open Websites/Domains: Social Media

Impact

T1657 Financial Theft

Affected products and versions in KelpDAO LayerZero Bridge Exploit

  • KelpDAO — rsETH Cross-Chain Bridge (LayerZero OApp)
    Vulnerable versions: v1.0.0 through v1.2.4
    Fixed in: v1.3.0 (pending release)
  • LayerZero Labs — LayerZero v2 Endpoint (KelpDAO DVN configuration)
    Vulnerable versions: KelpDAO 2-of-3 DVN configuration pre-2026-04-18
    Fixed in: 3-of-5 DVN configuration with zk co-verifier (post-2026-04-18)
  • KelpDAO — rsETH peripheral contracts on Arbitrum, Blast, Base, Mode, Scroll
    Vulnerable versions: All deployments prior to 2026-04-18 pause
    Fixed in: Post-remediation redeployment pending

Remediation for KelpDAO LayerZero Bridge Exploit

Patches

  • LayerZero Labs: publish updated DVN operator security baseline v2 and recommended minimum quorum guidance (expected Q2 2026)
  • KelpDAO bridge contracts v1.3.0: introduce mandatory zkLightClient co-verifier and per-message value cap as Solidity modifiers on the receive path
  • Polyhedra zkBridge v4 integration: provide Solidity reference implementation for source-chain burn proof verification

Immediate actions

  • Pause all LayerZero-based rsETH bridging and mint/release permissions on destination-chain OApps until DVN signing keys are rotated
  • Rotate signing keys for every DVN in the KelpDAO bridge configuration and audit HashiCorp Vault, AWS KMS, and any local key material on operator workstations
  • Freeze attacker-controlled addresses at centralized exchanges and stablecoin issuers (USDC, USDT) via Chainalysis Reactor / TRM Forensics sanctions-flagging workflows
  • Publish an indicator feed of attacker wallets, DVN attestation transactions, and forged packet hashes to LayerZero, DVN operators, and affected integrating protocols (Pendle, Morpho, Gearbox, Silo, EigenLayer)
  • Enforce per-message and per-time-window value caps on all LayerZero OApps controlling material value

Workarounds

  • Temporarily disable LayerZero-based rsETH bridging and route LRT transfers through Chainlink CCIP or native Ethereum L1 / L2 canonical bridges until DVN remediation is complete
  • Users holding destination-chain rsETH should evaluate exposure to any temporary de-peg and consider redeeming via KelpDAO's native Ethereum unstaking queue rather than selling on destination-chain DEXs
  • Integrating protocols (Pendle, Morpho, Gearbox, Silo Finance) should pause rsETH collateral deposits and apply conservative oracle bounds until peg stabilization is confirmed

Longer-term hardening

  • Reconfigure all high-value LayerZero OApps to require a zk-based or light-client-based source-chain state proof (Polyhedra zkBridge, Succinct SP1, Electron Labs) as a co-verifier independent of DVN attestations
  • Expand DVN quorum to 3-of-5 or 4-of-7 with strict personnel, cloud-provider, and geographic segregation between DVN operators
  • Mandate HSM or MPC custody (Fireblocks, Copper, Cubist, Coinbase Cloud Key Manager) for all DVN signing keys; disallow key material on operator workstations
  • Institute anti-phishing training and technical controls specifically targeted at recruiter/Dream-Job/TraderTraitor lures for all DVN operators and bridge engineering personnel
  • Engage a continuous on-chain anomaly-detection service (Chainalysis Hexagate, Forta, Hypernative, OpenZeppelin Defender Sentinel) to trigger automatic OApp pause on packet-flow anomalies
  • Adopt threshold ECDSA / FROST signing for DVN attestations so that single-node compromise cannot produce a valid signature

Weaknesses (CWE) in KelpDAO LayerZero Bridge Exploit

CWE-345, CWE-347, CWE-287, CWE-306, CWE-20, CWE-1240

Timeline of KelpDAO LayerZero Bridge Exploit

  • KelpDAO deploys rsETH cross-chain bridge on LayerZero v2 with a 2-of-3 DVN configuration (LayerZero Labs DVN, Google Cloud DVN, Kelp-operated DVN).
  • Radiant Capital multisig compromise ($50M) provides the public blueprint for Lazarus-style DVN/operator key exfiltration via recruiter-themed spearphishing on macOS; industry warnings issued but KelpDAO DVN configuration remains unchanged.
  • Fraudulent recruiter accounts (LinkedIn, Telegram) begin targeting KelpDAO bridge engineering staff and Google Cloud DVN operators with tier-1 DeFi job lures characteristic of Lazarus's TraderTraitor / Operation Dream Job playbook.
  • First malicious 'technical assessment' repository (BeaverTail-laced npm project on a Lazarus-controlled GitHub account) delivered to a KelpDAO bridge engineer.
  • BeaverTail JavaScript stager chained to InvisibleFerret Python backdoor and KandyKorn macOS implant establishes persistent C2 on first KelpDAO engineer's workstation; 1Password session tokens, AWS IAM keys, and Kelp DVN signing-key material exfiltrated.
  • A Google Cloud DVN operator is compromised via the same TraderTraitor chain, granting Lazarus access to the second DVN signing identity required for 2-of-3 quorum.
  • Attackers execute small (<=0.01 rsETH) forged LayerZero packets to Arbitrum, Blast, Base, Mode, and Scroll destination OApps to validate that the forged DVN attestations will be accepted on each chain.
  • KelpDAO pauses all LayerZero-based rsETH bridging operations and publishes an initial incident notice; rsETH de-pegs from ETH by ~7.4% before partially recovering.
  • Within 8 hours, attackers sell rsETH for ETH/USDC/USDT on KyberSwap, Uniswap v4, and 1inch; bridge a portion back to mainnet via Across and Stargate; begin layering via Tornado Cash nova (Gnosis), Railgun, and THORChain swaps to BTC and TRON USDT.
  • At 03:17 UTC, 38 forged LayerZero packets are submitted in a 42-minute burst; 116,500 rsETH (~$292M) is released on Arbitrum, Blast, Base, Mode, and Scroll against burns that never occurred on Ethereum mainnet.
  • KelpDAO and LayerZero Labs publish incident disclosures attributing the exploit to DVN operator compromise rather than a smart-contract flaw; rotation of DVN signing keys begins.
  • Pendle, Morpho Blue, Gearbox, and Silo Finance pause new rsETH collateral deposits; oracle bounds tightened to mitigate lending-market impact.
  • Mandiant and SlowMist publish forensic reports attributing to Lazarus Group; CISA issues an advisory on DPRK targeting of LRT and cross-chain bridge infrastructure; OFAC designates additional digital-asset addresses linked to the theft.
  • Chainalysis publishes the definitive on-chain analysis report, confirming wallet clustering with Ronin, Harmony Horizon, and Atomic Wallet attacker clusters and quantifying ~$292M total loss.
  • As of 2026-05-29, the KelpDAO incident is contained: rsETH recovery concluded (~117K rsETH replenished, 100% ETH backing by May 25), the bridge was re-secured (multi-DVN, 64-block confs, BailSec-audited) and is migrating to Chainlink CCIP. But it remains a live concern as perpetrator Lazarus/TraderTraitor stays highly active (Drift+Kelp = $575M in 18 days; DPRK = 76% of 2026 crypto theft), funds unrecovered.

Sources cited for KelpDAO LayerZero Bridge Exploit

Threats related to KelpDAO LayerZero Bridge Exploit

Detection coverage for TL-2026-0416

As of 2026-04-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0416 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats