Vulnerabilities · 147 days ago
KelpDAO’s failure was not just a stolen wallet. A 1-of-1 verifier and reliance on DVN RPC failover gave attackers a single point where they could forge a cross-chain instruction and make a massive rsETH drain look valid.
SecurityWeek and Infosecurity Magazine say North Korea-linked Lazarus Group stole about 116,500 rsETH, worth roughly $290 million, by poisoning LayerZero DVN RPCs and forcing failover to compromised infrastructure. Kelp paused contracts and blacklisted the attacker wallet, which blocked a follow-up attempt to drain another 40,000 rsETH.
The broader risk is architectural. If one verifier can authorize value movement, then compromising its supporting RPC layer can turn message validation into a theft path, and patching the protocol after the fact does not undo the trust failure.
5 sources covering this story
$290 Million Kelp DAO Crypto Heist Blamed on North Korea
The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.
North Korean Blamed for $290m KelpDAO Crypto Heist
North Korea’s Lazarus Group is pegged for a $290m crypto theft at KelpDAO
KelpDAO suffers $290 million heist tied to Lazarus hackers
State-sponsored North Korean hackers are likely behind the $290 million crypto-heist that impacted the KelpDAO DeFi project on Saturday.
North Korean hackers blamed for $290M crypto theft | TechCrunch
The hack against Kelp DAO is the largest crypto heist of the year so far.
The Record from Recorded Future
Crypto infrastructure company blames $290 million theft on North Korean hackers
A theft of nearly $300 million worth of cryptocurrency has been attributed to hackers from North Korea, as the industry grapples with the fallout of a wide-ranging incident involving multiple prominent platforms.
Part of the PlainSec briefing for 2026-04-21