Kelp DAO LayerZero Bridge Exploit event
Overview
On 18 April 2026 Kelp DAO's LayerZero-based rsETH bridge was exploited for roughly $292 million (about 116,500 rsETH), making it the largest crypto exploit of 2026 at the time. It was not a smart contract bug: attackers linked to North Korea's Lazarus Group socially engineered a LayerZero Labs developer in March 2026, harvested session keys, pivoted into LayerZero's RPC cloud environment and poisoned internal RPC nodes, combined with a DDoS component. LayerZero initially blamed Kelp's 1-of-1 decentralized verifier network configuration; Kelp responded that LayerZero's own default templates recommended that setup, and LayerZero later acknowledged it had 'made a mistake.' Kelp subsequently announced a migration of rsETH messaging to Chainlink CCIP.
Relations
No connections recorded for this entity in the DeFi Intel knowledge graph yet.
Frequently asked questions
How much was stolen?
Approximately $292 million, around 116,500 rsETH, with wrapped ether left stranded across roughly 20 chains.
Was this a smart contract vulnerability?
No. The attack targeted off-chain infrastructure — a socially engineered LayerZero Labs developer, stolen session keys and poisoned internal RPC nodes — rather than on-chain contract logic.
Who was blamed?
LayerZero first attributed it to Kelp's 1-of-1 DVN configuration, while Kelp pointed out LayerZero's default templates recommended that configuration; LayerZero later conceded it had made a mistake. The attackers were attributed to North Korea's Lazarus Group.
Sources
Facts on this page were verified against the following sources.