KelpDAO's LayerZero-powered bridge lost $292 million in rsETH on April 18 after a single compromised verifier approved a forged cross-chain message, exposing the fragility of 1-of-1 DVN setups across DeFi.
KelpDAO's LayerZero-powered bridge lost $292 million in rsETH on April 18 after a single compromised verifier approved a forged cross-chain message, exposing the fragility of 1-of-1 DVN setups across DeFi.

A forged burn message cleared by a lone LayerZero verifier emptied $292 million in rsETH from KelpDAO's cross-chain adapter on April 18, minting 116,500 tokens that never had backing.
"A protocol can pass a flawless code audit and still lose millions because of a compromised admin key," Ronghui Gu, co-founder of security firm CertiK, told Forbes.
The drain hit KelpDAO's Omnichain Fungible Token adapter on Ethereum, roughly 18 percent of rsETH's circulating supply. Attackers compromised LayerZero's internal RPC nodes, swapped legitimate binaries for counterfeit versions feeding fabricated data to the sole verifier, and DDoS-ed external nodes into silence. KelpDAO's emergency multisig paused core contracts about 46 minutes after the attack, at roughly 18:21 UTC, blocking a follow-up targeting another 40,000 rsETH. Recovery efforts have returned about $71 million, roughly a quarter of the stolen funds.
The breach triggered more than $10 billion in withdrawals across DeFi protocols, with Aave's total value locked dropping $6.28 billion in 48 hours and nine platforms freezing markets. Arbitrum's Security Council used emergency powers to seize 30,766 ETH from the attacker's wallet on-chain.
The exploit has forced protocols running LayerZero's OFT standard to reassess their DVN configurations. A 2-of-3 or 3-of-5 setup would have required attackers to compromise multiple independent validators. LayerZero publicly blamed KelpDAO for running a single-verifier setup; KelpDAO countered with Dune data showing 47 percent of LayerZero OApp contracts, more than 1,200 of them, use the same configuration.
Investigators including Mandiant, CrowdStrike, Elliptic and LayerZero linked the attack to TraderTraitor, a subgroup of North Korea's Lazarus Group. Combined with the $285 million Drift Protocol drain on April 1, the group accounts for $575 million in losses within 18 days, or at least 44 percent of the $1.3 billion stolen across crypto in the first half of 2026, per CertiK's Hack3d report.
KelpDAO is not an isolated case. AFX Trade lost $24.15 million in July when five compromised validator signatures cleared a two-thirds quorum on its Arbitrum bridge, and VerusCoin was hit twice on the same Ethereum bridge. The common thread is verification concentrated in too few signers.
For investors, the lesson is concrete: check how many validators stand between funds and a forged transaction before parking capital in any protocol that relies on cross-chain messaging. If the answer is one, the KelpDAO outcome is the template. KelpDAO's pause and partial recovery bought time, but the sector-wide de-risking from single-verifier bridges will determine whether liquid restaking protocols can rebuild trust.
This article is for informational purposes only and does not constitute investment advice.