📈 Get daily crypto insights that make you smarter about your money

Kelp DAO Loses $290 Million as Lazarus Group Exploits LayerZero RPC Nodes

The decentralized finance ecosystem suffered one of its most devastating blows in 2025 on April 10, when Kelp DAO lost approximately $290 million worth of rsETH in a sophisticated attack attributed to the North Korean Lazarus Group. The exploit targeted LayerZero’s cross-chain infrastructure through a multi-stage assault on the protocol’s Decentralized Verification Network, exposing critical vulnerabilities in validator security configurations that many DeFi platforms had overlooked.

The Exploit Mechanics

The attackers executed a carefully orchestrated multi-phase campaign against LayerZero’s DVN infrastructure. Rather than targeting a smart contract vulnerability, the Lazarus Group operatives focused their efforts on the Remote Procedure Call node layer — the foundational infrastructure responsible for validating cross-chain messages. First, they compromised two independent RPC nodes, replacing their legitimate software with malicious binaries specifically engineered to intercept and manipulate transaction data. Once the compromised nodes were operational, the attackers launched a massive distributed denial-of-service attack against the remaining legitimate nodes, flooding them with traffic until they became unresponsive. This dual-pronged approach effectively forced the entire validation system to route all requests through the now-compromised malicious nodes, creating the perfect conditions for authorizing fraudulent cross-chain transactions that drained rsETH from Kelp DAO’s contracts.

Affected Systems

The attack had catastrophic consequences specifically for Kelp DAO and its liquid staking operations. Approximately $290 million worth of rsETH — Kelp’s liquid staking token representing staked Ethereum across multiple protocols — was siphoned from the DAO’s contracts. The sudden massive sell pressure on decentralized exchanges triggered significant price volatility for rsETH, sending shockwaves through the broader liquid staking ecosystem. LayerZero’s post-mortem revealed a critical detail: the protocol had recommended that Kelp DAO employ a multi-DVN setup using multiple independent validators for message verification. However, Kelp DAO maintained only a single-validator structure for its rsETH operations, creating a single point of failure that the attackers expertly exploited. LayerZero emphasized that no other assets or applications on its network were affected by this incident, as the vulnerability was specific to Kelp DAO’s application-level configuration.

The Mitigation Strategy

In the aftermath of the exploit, LayerZero issued urgent security advisories to all protocols utilizing its cross-chain infrastructure. The primary recommendation centered on implementing multi-DVN configurations that distribute validation across multiple independent entities, eliminating single points of failure. The protocol also recommended enhanced monitoring of RPC node behavior, including anomaly detection systems capable of identifying unusual traffic patterns or unexpected software modifications. For Kelp DAO specifically, emergency measures included pausing all cross-chain rsETH transfers, coordinating with major decentralized exchanges to flag and freeze exploited funds, and engaging blockchain forensics firms to trace the movement of stolen assets. The broader DeFi community responded by conducting urgent security audits of their own validator configurations, with several prominent protocols proactively upgrading to multi-DVN setups even before receiving direct recommendations.

Lessons Learned

The Kelp DAO exploit serves as a stark reminder that infrastructure-level security is just as critical as smart contract auditing. The attack pattern mirrors previous high-profile bridge hacks — the $625 million Ronin Bridge exploit in 2022 and the $326 million Wormhole exploit — where attackers targeted validator infrastructure rather than contract code. Key takeaways include the absolute necessity of multi-validator configurations for any protocol handling significant value, the importance of real-time monitoring for DDoS attacks against validation nodes, and the growing sophistication of state-sponsored hacking groups like Lazarus. Bitcoin was trading at approximately $79,626 and Ethereum at $1,522 at the time of the attack, meaning the $290 million loss represented a substantial hit to the DeFi ecosystem’s total value locked.

User Action Required

Users who held rsETH or interacted with Kelp DAO’s liquid staking products should immediately check their wallet balances and transaction history. Those affected should follow Kelp DAO’s official communication channels for updates on recovery efforts and potential compensation plans. All DeFi users should review the security configurations of protocols they interact with, specifically checking whether platforms employ multi-validator setups for cross-chain operations. Consider diversifying liquid staking positions across multiple providers to minimize exposure to single-protocol failures. Enable transaction simulation tools before approving any cross-chain transfers, and maintain awareness that infrastructure-level attacks are becoming the primary threat vector in DeFi.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Kelp DAO Loses $290 Million as Lazarus Group Exploits LayerZero RPC Nodes”

  1. compromising RPC nodes instead of smart contracts is a terrifying escalation. lazarus keeps adapting and the defense side is always 3 steps behind

    1. rpc_ghost the defense side is always 3 steps behind because they have budgets and lawyers. Lazarus has time and state funding. asymmetric warfare applies here too

      1. rpc_truth_ is right about the asymmetry. lazarus has infinite time and state backing. defenders have quarterly budgets and compliance meetings

  2. 290M and it barely made mainstream news. if a traditional bank lost that much it would be front page for a week

  3. ddos_the_dinos

    the DDoS on remaining legit nodes while the malicious ones were active is the real masterstroke here. they essentially created a controlled information environment

    1. ddos_the_dinos the DDoS was the kill shot. you cant even tell which nodes are compromised when the legit ones are down. byzantine general problem in real time

  4. had a small rsETH position. pulled everything out of liquid staking protocols within an hour of seeing this. trust in the infra layer is completely broken for me rn

    1. Kristina M. pulling everything out of liquid staking because of an RPC attack is exactly the overreaction that causes the next cascade. the staking was fine, the cross-chain layer failed

    2. pulling everything out of liquid staking is the wrong takeaway. the issue was LayerZero DVN config, not the staking primitive itself. rsETH got hit because cross-chain validation failed, not because liquid staking is broken

      1. deadzone_ agree the staking primitive wasnt broken but rsETH is never recovering trust. users dont distinguish between layers and thats a problem for the whole sector

      2. deadzone is right that staking itself wasnt the issue. cross-chain validation was the weak link. but users dont distinguish between the two when deciding where to park funds

  5. Lazarus compromising 2 RPC nodes and then DDoS-ing the rest is next level. they didnt even need a smart contract bug, just social engineering on infrastructure

  6. Lazarus compromising RPC nodes while everyone was watching smart contracts is the definition of asymmetric warfare. $290M and the attack vector was infrastructure 101

  7. $290M in rsETH gone because validators didnt isolate their RPC nodes. this exploit will be studied for years because it targeted humans not code

  8. the DDoS timing was surgical. take down the honest nodes so only your malicious RPCs respond. byzantine consensus cant help you when 2 of 3 visible nodes are lying

    1. the DDoS timing was the real genius move. overload the honest nodes so only your compromised RPCs are responding. classic byzantine general exploit executed at nation-state level

  9. staking_insure_

    290M gone because 2 RPC nodes got swapped. the entire DVN model assumes node operators have better security than the protocol itself. clearly they dont

    1. dvn_config_nightmare_

      staking_insure_ the DVN model requires independent operators but LayerZero let anyone run an RPC node with zero verification. 2 compromised nodes and 290M gone

    2. validator_ops_

      staking_insure_ 2 RPC nodes compromised out of how many total? if the DVN quorum only needs 2 of 3 then the whole model is one breach away from catastrophic failure by design

      1. node_isolation_

        validator_ops_ the quorum threshold is the core issue. 2-of-3 means compromising just 2 nodes gives you full control. LayerZero needs mandatory independent verification with much higher thresholds for TVL over 100M

        1. signal_corridor

          node_isolation_ 2-of-3 quorum for 290M TVL is insane. should be minimum 5-of-7 with geographic distribution for anything over 50M

      2. validator_ops_ if the quorum only needs 2 of 3 visible nodes then the architecture is fundamentally broken. no amount of auditing fixes a bad threshold model

  10. multi-stage RPC compromise plus DDoS on legit nodes is nation-state level ops. no DeFi protocol can defend against that alone

  11. Lazarus targeting RPC nodes instead of smart contracts shows they adapt faster than security teams. $290M gone and the vulnerability was at the infrastructure layer nobody was watching

    1. the defense side isnt 3 steps behind, they just dont have nation-state backing. lazarus has essentially unlimited resources

      1. Lazarus has been doing this since 2017 and the defense playbook has barely changed. individual protocols cant match state-level opsec

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,784.00-0.2%ETH$1,916.49+0.1%SOL$76.27+2.0%BNB$602.84+1.4%XRP$1.04+0.2%ADA$0.1988-0.5%DOGE$0.0701-0.1%DOT$0.8099-1.0%AVAX$6.48-0.7%LINK$8.33+0.9%UNI$3.96-0.7%ATOM$1.38+0.5%LTC$46.13+1.4%ARB$0.0777-1.3%NEAR$1.62+2.2%FIL$0.7102+1.0%SUI$0.6920+1.3%BTC$64,784.00-0.2%ETH$1,916.49+0.1%SOL$76.27+2.0%BNB$602.84+1.4%XRP$1.04+0.2%ADA$0.1988-0.5%DOGE$0.0701-0.1%DOT$0.8099-1.0%AVAX$6.48-0.7%LINK$8.33+0.9%UNI$3.96-0.7%ATOM$1.38+0.5%LTC$46.13+1.4%ARB$0.0777-1.3%NEAR$1.62+2.2%FIL$0.7102+1.0%SUI$0.6920+1.3%
Scroll to Top