LayerZero releases report on KelpDAO attack: North Korean hacker group implicated, will adjust security strategy

ME News reports that on May 20 (UTC+8), LayerZero Labs released its latest incident report stating that on April 18, 2026, the KelpDAO rsETH cross-chain bridge built on its cross-chain communication protocol was attacked, with approximately 116,500 rsETH (about $292 million) stolen. Multiple security agencies including Mandiant, CrowdStrike, and independent researchers attributed this attack to the North Korea-linked hacker group TraderTraitor (UNC4899). The report shows that the attack began on March 6, 2026. The attackers used social engineering to infiltrate LayerZero developer accounts, obtain session keys, and penetrate the RPC cloud environment, further corrupting internal RPC node data and manipulating return results to deceive monitoring systems and the Decentralized Verification Network (DVN). Subsequently, the attackers launched a denial-of-service attack against external RPC providers, causing the verification system to rely on the compromised nodes to generate forged cross-chain proofs, thereby successfully extracting funds. LayerZero pointed out that the core vulnerability in this incident was that the affected application adopted a "single-verifier" configuration, which allowed the target contract to release assets upon receiving only a single valid signature, leading to the theft of rsETH. After the incident, LayerZero Labs announced adjustments to its security strategy, including no longer allowing its own DVN to serve as the sole signing party in single-verifier configurations, while rebuilding the affected cloud infrastructure and introducing short-term credentials, instant permission upgrades, and multi-party approval mechanisms to strengthen security. Additionally, zeroShadow and law enforcement agencies have launched investigations and asset tracking. LayerZero stated that it will continue to work with ecosystem partners to strengthen cross-chain security systems to address increasingly sophisticated nation-state attack threats. (Source: ODAILY)
ZRO-3.67%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments