Lazarus Group's $292M DeFi Hack Still Shaking Crypto Markets Months Later
North Korea's Lazarus Group carried out one of the year's most costly decentralised finance (DeFi) breaches, exploiting a vulnerability in KelpDAO's LayerZero bridge integration to steal $292 million. The attack, which occurred in April, remains the largest DeFi exploit recorded so far this year.
Four months on, the fallout continues to affect the broader DeFi sector, with total value locked in related platforms like Aave still down significantly compared to pre-hack levels. This shows how a single successful attack on interconnected financial infrastructure can have long-lasting ripple effects across an entire ecosystem, well beyond the initial victim.
While this incident targeted a large DeFi protocol, it highlights a broader lesson for any business relying on third-party integrations, bridges, or connected financial platforms: vulnerabilities in one component can expose the whole system, and trust can take a long time to rebuild after a major breach.