logo

KelpDAO Bridge Hack: $292M Stolen by Lazarus Group Exploit

ID: 2ed0c7e8-19e5-5483-a11c-df80535c260b

STIX ID: report--2ed0c7e8-19e5-5483-a11c-df80535c260b

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

...
...

**KelpDAO Bridge Hack (April 18, 2026):** A sophisticated attack attributed to North Korea's Lazarus Group (TraderTraitor) compromised two RPC nodes and used DDoS against clean nodes to force reliance on the compromised nodes, enabling theft of ~116,500 rsETH (~$292M). The exploit exploited a single-verifier (1/1) configuration, prompted over $10B in withdrawals from Aave, and has led LayerZero to stop supporting single-verifier apps while coordinating with law enforcement to track funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.