Industry News

KelpDAO Bridge Hack Drains $292M After Single Verifier Fails, Lazarus Group Suspected

Crypto Briefing · 8 Sept 2026
Key Takeaway Businesses relying on third-party financial or blockchain infrastructure should ask providers whether critical approval processes depend on a single point of failure, and demand redundancy and independent verification wherever money movement is automated.

A cross-chain bridge adapter used by DeFi platform KelpDAO was exploited on April 18 for approximately $292 million in rsETH, after attackers found and abused a critical weakness: the system relied on just one verifier to approve transactions. The breach drained 116,500 rsETH, around 18% of the token's circulating supply, and triggered more than $10 billion in withdrawals across other DeFi protocols in the following hours.

The bridge used a 1-of-1 Decentralized Verifier Network, meaning only one validator needed to approve a transaction before funds were released. Attackers compromised internal infrastructure nodes belonging to LayerZero, the bridge provider, and replaced legitimate software with fake versions that fed false data to the verifier. They also launched a denial-of-service attack against backup nodes to force the system to rely solely on the compromised infrastructure, allowing a forged transaction to trick the system into releasing funds that had never actually been burned on the other chain.

KelpDAO's emergency team paused the affected contracts around 46 minutes after the attack began, preventing a follow-up attempt to steal an additional 40,000 rsETH, though the initial damage had already occurred. Investigators have preliminarily linked the attack to North Korea's Lazarus Group, and around $71 million of the stolen funds has since been recovered.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Crypto Briefing. We link back to every original so you can read it yourself.