Refreshed 1h ago· updates every 6h

KelpDAO (2026) — Crypto Hack

Partially Recovered
Apr 18, 2026·
EthereumArbitrum
Amount Stolen
$292.0M
Unbacked rsETH minted cross-chain
Recovered
$71.0M
24% of stolen funds

Attackers exploited a LayerZero OFT bridge verification flaw and poisoned RPC to mint unbacked rsETH and steal ~$292M, linked to North Korean Lazarus Group.

Summary

Attackers exploited a LayerZero OFT bridge verification flaw and poisoned RPC to mint unbacked rsETH and steal ~$292M, linked to North Korean Lazarus Group.

How It Was Compromised — Bridge Exploit via Cross-chain verification flaw via socially engineered poisoned RPC

Bridge ExploitCross-chain verification flaw via socially engineered poisoned RPC

On April 18, 2026, KelpDAO's LayerZero OFT bridge was exploited through a cross-chain verification flaw combined with a socially engineered poisoned RPC node. The attackers minted unbacked rsETH and drained approximately $292M across Ethereum and Arbitrum. Blockchain investigators linked the operation to North Korea's Lazarus Group based on fund-flow patterns. Approximately $71M was frozen on Arbitrum through coordinated validator action.

Fund Flow & Laundering Analysis

Portions frozen on Arbitrum by validators (~$71M). Remaining funds moved through cross-chain bridges and DEX swaps; Lazarus Group attribution based on on-chain fund-flow patterns.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.