Kelp blames LayerZero for approving $292 million hack setup

Kelp DAO has accused LayerZero personnel of approving the 1-of-1 verifier setup blamed for a $292 million exploit on its rsETH bridge. The protocol plans to migrate from LayerZero's OFT standard to Chainlink's CCIP. The hack has been linked to North Korea's Lazarus Group.

Kelp DAO released a memo titled “Setting the Record Straight Around the LayerZero Bridge Hack,” claiming LayerZero reviewed its configurations for over 2.5 years across eight integration discussions without warning of security risks in the 1-of-1 verifier setup. A screenshot from Telegram shows a LayerZero team member stating: “No problem on using defaults either — just tagging [redacted] here since he mentioned you may have wanted to use a custom DVN setup for verifying messages, but will leave that to your team!” Kelp argues these defaults were the 1-of-1 LayerZero Labs DVN configuration that enabled the exploit, which drained 116,500 rsETH worth roughly $292 million. Two additional forged transactions exceeding $100 million were processed before Kelp paused its contracts, according to the protocol. Kelp alleges it had to flag the exploit to LayerZero, questioning the company's monitoring. Data from CoinGecko citing Dune Analytics indicates 47% of active LayerZero OApp contracts used a similar 1-of-1 setup, exposing over $4.5 billion in value. LayerZero's April 19 postmortem blamed Kelp's reliance on LayerZero Labs as the sole verifier, calling it a contradiction of recommended multi-DVN models. LayerZero has since banned 1-of-1 configurations and stated its protocol functioned as intended. A LayerZero spokesperson responded: “The claim that Kelp used default configurations of LayerZero is inaccurate. They deployed multiDVN and then manually downgraded to a 1/1.” The spokesperson added that bug bounty exclusions cover application-level choices like verifier networks. In response, Kelp is migrating rsETH to Chainlink's Cross-Chain Interoperability Protocol. LayerZero did not further comment by publication. As first reported by CoinDesk on May 5, 2026.

Mga Kaugnay na Artikulo

Dramatic courtroom scene depicting lawyers arguing over frozen Ethereum coins from Kelp DAO hack amid terrorism claims.
Larawang ginawa ng AI

Aave fights to unfreeze $71 million amid Kelp DAO hack court battle

Iniulat ng AI Larawang ginawa ng AI

A federal case is unfolding over $71 million in frozen cryptocurrency following the Kelp DAO exploit, as Aave seeks to release the funds for DeFi recovery. Victims of decades-old North Korean terrorist acts have filed a restraining notice against Arbitrum DAO, claiming the 30,765 ETH as DPRK-linked property. The dispute pits recent hack victims against long-standing terrorism judgment holders.

LayerZero has acknowledged it made a mistake by allowing its own verifier network to secure high-value assets in a vulnerable setup. The admission comes weeks after a $292 million hack on Kelp DAO that the company had initially blamed on the developer. The firm says its core protocol remained unaffected.

Iniulat ng AI

A $292 million exploit on Kelp DAO has shaken decentralized finance (DeFi) lending markets, prompting industry insiders to call for stronger security measures. Despite the setback, experts view it as a temporary hurdle rather than a barrier to institutional adoption. Wall Street firms continue advancing into onchain finance amid the fallout.

Thorchain confirmed a suspected multichain exploit on May 15 that drained about $10 million from users across several networks. The protocol activated emergency halts and has now launched a recovery portal for affected wallets.

Iniulat ng AI

Thorchain suspended trading for about 12 hours after blockchain researcher ZachXBT flagged a suspected $10 million exploit across multiple networks. The liquidity protocol took the action following the alert on a potential breach. Its native RUNE token fell by double digits in response.

Former Ethereum Foundation researcher Dankrad Feist has called for a new community-led organization with a $1 billion treasury to better align incentives with Ethereum's growth.

Iniulat ng AI

Payward, the parent company of cryptocurrency exchange Kraken, has agreed to acquire Hong Kong-based Reap Technologies for up to $600 million in a cash-and-stock deal. The transaction values Payward at $20 billion and represents the company's largest acquisition to date.

 

 

 

Gumagamit ng cookies ang website na ito

Gumagamit kami ng cookies para sa analytics upang mapabuti ang aming site. Basahin ang aming patakaran sa privacy para sa higit pang impormasyon.
Tanggihan