KelpDAO Bridge Hack Drains $292M After Single Verifier Fails, Lazarus Group Suspected
A cross-chain bridge adapter used by DeFi platform KelpDAO was exploited on April 18 for approximately $292 million in rsETH, after attackers found and abused a critical weakness: the system relied on just one verifier to approve transactions. The breach drained 116,500 rsETH, around 18% of the token's circulating supply, and triggered more than $10 billion in withdrawals across other DeFi protocols in the following hours.
The bridge used a 1-of-1 Decentralized Verifier Network, meaning only one validator needed to approve a transaction before funds were released. Attackers compromised internal infrastructure nodes belonging to LayerZero, the bridge provider, and replaced legitimate software with fake versions that fed false data to the verifier. They also launched a denial-of-service attack against backup nodes to force the system to rely solely on the compromised infrastructure, allowing a forged transaction to trick the system into releasing funds that had never actually been burned on the other chain.
KelpDAO's emergency team paused the affected contracts around 46 minutes after the attack began, preventing a follow-up attempt to steal an additional 40,000 rsETH, though the initial damage had already occurred. Investigators have preliminarily linked the attack to North Korea's Lazarus Group, and around $71 million of the stolen funds has since been recovered.