Svmuu reports that LayerZero Labs has released a recent incident report stating that on April 18, 2026, the KelpDAO rsETH cross-chain bridge, built on its cross-chain communication protocol, suffered an attack resulting in the theft of approximately 116,500 rsETH (around $292 million). Multiple security organizations, including Mandiant, CrowdStrike, and independent researchers, have attributed this attack to the North Korea-linked hacker group TraderTraitor (UNC4899).
According to the report, the attack began on March 6, 2026. The attackers compromised a LayerZero developer account through social engineering, obtained session keys, and penetrated the RPC cloud environment. They further contaminated internal RPC node data and manipulated the returned results to deceive monitoring systems and the Decentralized Verification Network (DVN). Subsequently, the attackers launched a denial-of-service attack against external RPC providers, forcing the verification system to rely on the compromised nodes to generate forged cross-chain proofs, thereby successfully extracting the funds.
LayerZero pointed out that the core vulnerability of this incident lay in the affected application adopting a "single-verifier" configuration. This allowed the target contract to execute asset releases upon receiving only a single valid signature, leading to the theft of rsETH.
Following the incident, LayerZero Labs announced an adjustment to security policies. This includes no longer allowing its own DVN to act as the sole signer in a single-verifier configuration, rebuilding the affected cloud infrastructure, and introducing short-term credentials, instant permission upgrades, and multi-party approval mechanisms to enhance security. Additionally, zeroShadow and law enforcement agencies have initiated investigations and asset tracing. LayerZero stated it will continue to collaborate with ecosystem partners to strengthen the cross-chain security framework to address increasingly sophisticated nation-state attack threats.
LayerZero Releases KelpDAO Attack Report: North Korean Hackers Suspected of Involvement, Security Policies to Be Adjusted
No AI analysis yet. Tap the "AI Analysis" button above to generate one now.
Source:Odaily · Source Link
Disclaimer: This content reflects only the author’s personal views and does not constitute any investment or financial advice. If you discover any content that violates regulations,Click to Report
24H Trending
-
1
Aethir (ATH) Token Value Analysis: Decentralized Cloud Computing Project Potential and Risk Assessment
-
2
NOAH Coin Analysis: Distinguishing Between Controversial Projects and Active Payment Infrastructure
-
3
RIKEN Coin Value Analysis: Numerous Projects Share the Same Name, What's Its Investment Potential?
-
4
FXBK Coin Analysis: What Is It? Is It Worth Investing In?
-
5
Beginner's Guide to Bitcoin Trading: A Comprehensive Analysis of Security Risks and Prevention Strategies
-
6
Bitcoin rises above $77,000, bucking tech selloff driven by AI safety concerns and rising oil prices
-
7
Taiwan to open second quasi-diplomatic mission in the Philippines, sources say
-
8
Cosco Shipping Heavy Industry Completes China IPO Guidance Registration
-
9
Samsung Display develops world's first 6.9-inch mobile OLED panel with 2K resolution, 165Hz refresh rate, and 30% lower power consumption
-
10
ATPAD (AtomPad) Project Status Analysis: An Inactive Cryptocurrency
Markets Today
Recommended Reading








