Single Verifier Let Lazarus Forge Cross-Chain Messages

KelpDAO’s failure was not just a stolen wallet. A 1-of-1 verifier and reliance on DVN RPC failover gave attackers a single point where they could forge a cross-chain instruction and make a massive rsETH drain look valid. SecurityWeek and Infosecurity Magazine say North Korea-linked Lazarus Group stole about 116,500 rsETH, worth roughly $290 million, by poisoning LayerZero DVN RPCs and forcing failover to compromised infrastructure. Kelp paused contracts and blacklisted the attacker wallet, which blocked a follow-up attempt to drain another 40,000 rsETH. The broader risk is architectural. If one verifier can authorize value movement, then compromising its supporting RPC layer can turn message validation into a theft path, and patching the protocol after the fact does not undo the trust failure.

Part of the PlainSec briefing for 2026-04-21

Editions

Sources