BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

How Did the KelpDAO Exploit Reshape LayerZero’s Security Model?

The KelpDAO exploit forced LayerZero to end support for single-verifier security setups and rebuild its default configuration around multiple independent verifiers. On April 18, 2026, attacke

AnonymousCryptoCompass newsroom
August 31, 2026
5 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

The KelpDAO exploit forced LayerZero to end support for single-verifier security setups and rebuild its default configuration around multiple independent verifiers. 

On April 18, 2026, attackers linked to North Korea's Lazarus Group stole roughly $292 million in rsETH from KelpDAO's cross-chain bridge by compromising the infrastructure behind LayerZero's verification system, not the smart contracts themselves. The incident pushed LayerZero to admit fault, apologize publicly, and rewrite how it handles high-value applications going forward.

What Happened in the KelpDAO Exploit?

KelpDAO is a liquid restaking protocol that lets users stake ETH and receive rsETH, a token representing their staked position, which can then move across chains. To move rsETH between blockchains, KelpDAO relied on LayerZero's messaging system.

  • Attackers gained access to a LayerZero Labs developer's session keys through social engineering, starting March 6, 2026
  • They used that access to breach RPC (Remote Procedure Call) nodes, the servers that read and relay blockchain data
  • They patched the memory on those nodes so LayerZero's tools saw normal-looking responses while receiving manipulated data
  • They launched a denial-of-service attack on an external RPC provider, forcing the system to rely on the compromised node
  • The forged data let attackers push a fraudulent cross-chain message, draining 116,500 rsETH worth about $292 million

KelpDAO detected the anomaly and blocked the attacker at 18:23 UTC, then reached out to the Security Alliance's SEAL 911 emergency response team at 18:34 UTC, both within roughly an hour of the incident starting, according to SEAL's own incident log. 

The quick response also blocked a second attempt to steal an additional 40,000 rsETH, worth about $95 million, using a follow-up forged packet. The Arbitrum Security Council separately froze more than 30,000 ETH of the attacker's downstream funds.

A Look Into Single-Verifier Setup

LayerZero's security model depends on Decentralized Verifier Networks, or DVNs, which confirm that a cross-chain message is legitimate before the destination chain acts on it.

The 1/1 Configuration Problem

KelpDAO ran a 1-of-1 DVN configuration, meaning a single verifier, operated by LayerZero Labs, was enough to approve a transaction. LayerZero had recommended multi-verifier setups requiring consensus across independent DVNs, which would have made the forged message ineffective even with one compromised verifier. KelpDAO used the single-verifier option anyway.

A Disputed Responsibility

LayerZero initially said the protocol "functioned exactly as intended" and placed responsibility on KelpDAO's configuration choice. KelpDAO pushed back, pointing to LayerZero's own onboarding documents and quickstart examples, which listed the single-verifier setup as a standard option. About three weeks after the attack, LayerZero reversed its position, stating it "made a mistake" by letting its DVN act as a sole verifier for high-value transactions and apologizing for its handling of the response.

What Security Changes Has LayerZero Made?

LayerZero announced several concrete changes following the exploit:

  • The LayerZero Labs DVN no longer services any 1/1 configuration
  • Default pathways now require five verifiers where available, with a floor of three on chains that only support three DVNs
  • A second DVN client, written in Rust, is being built for client-level diversity
  • RPC infrastructure has been reconfigured for more granular quorum controls
  • LayerZero's own multisig threshold is being raised from 3-of-5 to 7-of-10 using OneSig, an open-source multisig tool

LayerZero is also recommending that applications pin their own security configurations rather than rely on defaults, set block confirmations high enough to make reorganization effectively impossible, and consider running their own DVN as a required verifier.

How Has the Market Reacted?

KelpDAO has since moved its rsETH bridge to Chainlink's Cross-Chain Interoperability Protocol, and Solv Protocol shifted more than $700 million in tokenized bitcoin infrastructure away from LayerZero. 

But the protocol also gained a notable vote of confidence: on May 14, 2026, Fidelity's FCAT deployed an institutional-grade DVN on LayerZero, with Ondo Finance as its first integrator. LayerZero has said more than $9 billion moved across the protocol without incident in the weeks following the exploit, on an architecture it says has processed over $260 billion in total volume. 

As of late August 2026, ZRO, LayerZero's native token, trades near $1.17 to $1.21, up sharply over the past week, with a market cap around $415 million to $450 million, still well below its December 2024 high of $7.51.

Conclusion

The KelpDAO exploit showed that a blockchain's smart contracts can stay untouched while an off-chain trust layer still fails. LayerZero has since eliminated single-verifier configurations, raised its default verifier count, diversified its verifier software, and tightened its own internal multisig controls. 

The episode cost LayerZero two major integrations, drew a new institutional verifier onto the network, and renewed scrutiny of how cross-chain protocols document security defaults for developers.

Resources

  1. Incident statement by LayerZero: Official summary of the April 18, 2026 KelpDAO exploit and initial attribution
  2. Update by LayerZero: LayerZero's public apology and detailed list of post-exploit security changes
  3. Incident analysis by Security Alliance (SEAL): Independent incident timeline and DVN configuration recommendations
  4. Report by CoinDesk: LayerZero's reversal and admission of fault three weeks after the exploit
  5. Report by crypto.news: Full breakdown of the exploit mechanics and LayerZero's tightened bridge security policy
  6. Analysis by Chainalysis: On-chain breakdown of the attack timeline and KelpDAO's incident response
  7. Report by CoinDesk: KelpDAO's dispute of LayerZero's account of responsibility
  8. Announcement by FCAT: Fidelity's institutional DVN deployment on LayerZero with Ondo Finance
  9. ZRO price data by Coinbase: Live LayerZero token price, market cap, and circulating supply