$292 million lesson: Don't let a single person control the cross-chain bridge DVN.

View Original
MeNews
LayerZero releases KelpDAO attack incident report: North Korean hacker group accused of involvement and will adjust security strategies
ME News reports that on April 18, 2026, the KelpDAO rsETH cross-chain bridge was attacked, with approximately 116,500 rsETH (about $292 million) stolen, pointing to North Korean-linked hackers associated with TraderTraitor (UNC4899).
The attack began on March 6, with hackers infiltrating developer accounts through social engineering and penetrating RPC cloud services, forging cross-chain proofs, and using external RPC DDoS attacks to facilitate fund extraction.
The core issue was that a single validator configuration allowed assets to be released with just one signature.
LayerZero will adjust its strategy by disabling the sole signature requirement for DVN in single-signature scenarios, rebuilding cloud infrastructure, adding short-term credentials and multi-party approvals to enhance cross-chain security.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned