KelpDAO (2026) — Crypto Hack
Partially RecoveredAttackers exploited a LayerZero OFT bridge verification flaw and poisoned RPC to mint unbacked rsETH and steal ~$292M, linked to North Korean Lazarus Group.
Summary
Attackers exploited a LayerZero OFT bridge verification flaw and poisoned RPC to mint unbacked rsETH and steal ~$292M, linked to North Korean Lazarus Group.
How It Was Compromised — Bridge Exploit via Cross-chain verification flaw via socially engineered poisoned RPC
On April 18, 2026, KelpDAO's LayerZero OFT bridge was exploited through a cross-chain verification flaw combined with a socially engineered poisoned RPC node. The attackers minted unbacked rsETH and drained approximately $292M across Ethereum and Arbitrum. Blockchain investigators linked the operation to North Korea's Lazarus Group based on fund-flow patterns. Approximately $71M was frozen on Arbitrum through coordinated validator action.
Fund Flow & Laundering Analysis
Portions frozen on Arbitrum by validators (~$71M). Remaining funds moved through cross-chain bridges and DEX swaps; Lazarus Group attribution based on on-chain fund-flow patterns.