KelpDAO has completed the operational phase of the rsETH recovery plan, sending the final tranche of rsETH to the OFT adapter and fully restoring the bridge's backing. In April 2026, a North Korean threat actor compromised LayerZero Labs' internal RPC infrastructure and exploited a 1-of-1 DVN configuration on rsETH's bridge to steal roughly 116,500 rsETH (~$292 million), prompting a full protocol pause, a public dispute between KelpDAO and LayerZero over responsibility, and a coordinated recovery plan involving Aave and Kelp progressively refilling the drained OFT adapter lockbox over two weeks.
The KelpDAO team has announced the completion of the operational phase of the rsETH recovery plan, with the final tranche of 20,373.72 rsETH sent to the rsETH OFT adapter. Over the prior two weeks, ~116,000 rsETH were refilled into the rsETH OFT adapter by Aave and Kelp combined.
LayerZero Labs has published its formal incident report on the Apr. 18, 2026 KelpDAO rsETH exploit, with contributions from Mandiant, CrowdStrike, and zeroShadow. Mandiant and CrowdStrike attribute the attack to the DPRK with high confidence and to UNC4899 (also known as TraderTraitor, Jade Sleet, and Pressure Chollima) with medium confidence, with independent researchers tanuki42 and tayvano providing corroborating attribution by de-mixing the initial funding for the attacker's wallet. The total loss is confirmed at 116,500 rsETH (~$292 million). UNC4899 was previously responsible for the February 2025 Safe{Wallet} compromise that led to the $1.5 billion Bybit theft.
The breach began on Mar. 6, 2026, when a LayerZero Labs developer on the team maintaining RPC infrastructure was socially engineered into cloning a malicious GitHub repository that deployed two Rust-based macOS backdoors named FLATROOF (Telegram command-and-control) and ROOFDECK (Nostr command-and-control). The endpoint detection and response (EDR) software on the device did not detect the malware. From Mar. 30 through Apr. 16, the attacker used the developer's harvested session keys to access LayerZero Labs' Google Cloud Platform (GCP) and GitHub environments via consumer VPN services, performing reconnaissance and establishing further persistence. Between Apr. 16 and Apr. 18, the attacker moved laterally through Google Kubernetes Engine and poisoned the op-geth running processes on two clusters in two separate regions by injecting an ELF position-independent executable (CARVED1) and a monitor library (CARVED2), which together hooked Go's standard library syscall functions to intercept and tamper with HTTP and JSON RPC traffic in memory. The poisoned nodes were engineered to return correct responses to LayerZero Labs' monitoring tools while delivering forged responses to the DVN signing service. At 16:30 UTC on Apr. 18, the attacker initiated a denial-of-service attack against external RPC providers, forcing the LayerZero Labs DVN to fail over to the two poisoned internal nodes, and one hour and five minutes later the attacker unlocked 116,500 rsETH on Ethereum. The report confirms that DVN signer keys were not exfiltrated, no other LayerZero Labs infrastructure was compromised, and no other OApps, channels, or transactions were impacted.
LayerZero Labs detailed several layers of hardening implemented since the incident. The LayerZero Labs DVN signing service now inspects each channel's UlnConfig and refuses to sign any message where it is the sole required DVN, requires a multi-source RPC quorum with explicit diversity across providers, hosting environments, and geographies for security-related queries, and is being supplemented by a new Rust client to provide client diversity within the team's own DVN. The compromised cloud environment was fully rebuilt rather than patched, with no legacy credentials, service accounts, or configurations carried over. Privileged operations now require just-in-time elevation with per-session authentication, long-lived service account keys have been replaced with short-lived rotating credentials, multi-person review is required for IAM changes that expand permissions, and device context is re-evaluated on every administrative request rather than only at login. An extended detection and response (XDR) system was deployed across the cloud environment, and the EDR on LayerZero Labs devices was upgraded to a more aggressive enforcement posture. The team additionally stated that it will update protocol defaults so that all channels use no less than a 3-of-3 DVN configuration, and that listing of OFT assets on its first-party offerings, including the Value Transfer API and Stargate Finance, will require applications to maintain a multi-DVN security stack and multi-RPC infrastructure.
The KelpDAO team has confirmed that rsETH protocol operations are fully online, with rsETH fully backed across mainnet and all L2s, and deposits and withdrawals live on both networks. Backing can be verified with a curated webpage supported by the team. The exchange rate was updated at 16:45 CET on May 15, reflecting all staking rewards accrued by rsETH holders throughout the full pause window. EIGEN rewards corresponding to the entire pause period are now distributable to rsETH holders and can be claimed on Kelp’s dedicated claim portal.
The KelpDAO team has announced that rsETH withdrawals are now live, with bridging and claims also active as part of the coordinated restart plan. Exchange rates will be updated at ~14:30 UTC on May 15, 2026, alongside Eigen claims, with the rate update intended to reflect all staking rewards accrued to rsETH holders during the pause period. Deposits are expected to reopen after a "brief stabilization window."
The KelpDAO team has confirmed that Aave has transferred the first tranche of rsETH into the LayerZero OFT Adapter under the coordinated restart plan, with bridging between Ethereum mainnet and L2s now resumed. rsETH contracts will be unpaused for withdrawals within 24 hours, with deposits reopening and exchange rates updating within 48 hours. The team states that the exchange rate update will accrue staking rewards from the pause period to rsETH holders. Remaining tranches from Aave's recovery guardian and Kelp will be sent over the next two weeks to fully refill the OFT Adapter lockbox.
The KelpDAO team has provided an update on rsETH recovery operations, announcing the start of backing refills, a tentative resumption of withdrawals within 24 hours of the first tranche, and the completed burn of the exploiter's rsETH on Arbitrum. 117,132 rsETH will be progressively refilled from the Aave Recovery Guardian and Kelp Recovery Safe into the LayerZero OFT adapter on Ethereum mainnet over the next two weeks, with the team noting that rsETH on mainnet and L2s has remained fully backed throughout the recovery period. Deposits, redemptions, bridging, and claims will all resume once contracts are unpaused.
The team also confirmed that BailSec has audited the LayerZero bridging hardening measures announced last week, which raised verification to four independent attestors, increased block confirmations from 42 to 64, and deprecated all L2-to-L2 routes.
LayerZero Labs has published a disclosure acknowledging that internal RPCs used by the LayerZero Labs Decentralized Verifier Network (DVN) were compromised by the Lazarus Group, who poisoned the DVN's source of truth while an external RPC provider faced a simultaneous distributed denial-of-service (DDoS) attack. The LayerZero protocol itself was unaffected. The incident impacted a single application.
The team acknowledged that permitting the LayerZero Labs DVN to operate as a 1/1 DVN for high-value transactions was a mistake. The team intends to be more active in educating developers and monitoring how applications build on the protocol to ensure they are configured safely. Actions taken since the incident include ending 1/1 DVN configurations, migrating defaults to 5/5 (or at least 3/3 where only three DVNs exist), developing a Rust-based second DVN client, and implementing a robust RPC quorum configuration. The team also launched OneSig to strengthen multisig signing security and plans to raise multisig thresholds to 7/10 across supported chains.
Developer recommendations from the team include pinning all configurations, setting sufficiently high block confirmations, using DVNs with at least two parties (three to five preferred), and considering a self-hosted DVN in a required security configuration. The team is also building "Console," a unified platform for asset issuers to configure, deploy, and manage security, incorporating automated anomaly detection and OneSig integration. A formal post-mortem is pending completion of work by external security partners.
Addressing a recent concern surrounding prior LayerZero multisigs signing keys for DeFi transactions, Layer Zero Labs has also separately disclosed that 3.5 years ago a multisig signer used a hardware wallet for a personal trade. That signer was removed and wallets were rotated at the time, with stronger signing practices and anomaly detection introduced afterward.
LayerZero Labs CEO Bryan Pellegrino has responded to the KelpDAO team's most recent statement, contesting the claim that the 1-of-1 DVN configuration used on rsETH was LayerZero's documented default. Pellegrino states that rsETH was originally deployed in February 2024 using LayerZero's standard default of a multi-DVN setup (LayerZero Labs + Google), and that the KelpDAO team manually migrated both routes to a 1-of-1 configuration on Apr. 1, 2024, citing send-side and receive-side configuration transactions on Ethereum.
Pellegrino additionally states that the KelpDAO team's Unichain deployment, opened on Apr. 1, 2025, was also manually configured as 1-of-1 from the outset, with the DVN config transaction following six seconds after the pathway's setPeer transaction. He notes that the Unichain to Ethereum and Ethereum to Unichain defaults were set to DeadDVN at the time, a contract that explicitly blocks transactions from applications that have not manually configured their DVNs, making use of the defaults technically impossible on those routes.
Pellegrino cites six documentation references spanning LayerZero's integration checklist, ONFT quickstart guide, and Starknet FAQ that explicitly advise against 1-of-1 DVN configurations in production environments. He also states that LayerZero Labs provided a specific recommendation to the KelpDAO team for a 2-of-3 multi-DVN configuration prior to the incident. Regarding overall exposure, Pellegrino states that almost all volume on 1-of-1 configurations was specific to rsETH, countering the KelpDAO team's claim that ~47% of OApps deployed on LayerZero used the same setup. Pellegrino states that a full post-mortem will be published after external security firms complete their review.
The KelpDAO team has published a statement disputing LayerZero's public characterization that the Apr. 18, 2026 exploit resulted from a KelpDAO misconfiguration. The team states that the 1-of-1 Decentralized Verifier Network (DVN) configuration used was LayerZero's approved and documented default, and that around 47% of the 2,665 OApps deployed on LayerZero used the same setup. According to the statement, the exploit originated from a compromise of LayerZero Labs' own offchain DVN infrastructure via an RPC-spoofing attack. The team states it detected the attack and paused rsETH bridge contracts within the hour on Apr. 18, 2026, and that its intervention blocked two additional forged transactions totaling more than $100 million. The statement further claims that LayerZero's bridging infrastructure remained active after Kelp paused its contracts.
As a result of the exploit, KelpDAO has additionally announced plans to migrate rsETH from LayerZero's Omnichain Fungible Token (OFT) standard to Chainlink's Cross-Chain Interoperability Protocol (CCIP) and Cross-Chain Token (CCT) standard across all supported chains.
Aave Labs has shared DeFi United's technical implementation plan to restore rsETH's backing and clear ~107,000 rsETH of stolen collateral that remains active across seven exploiter addresses on Aave and Compound. The plan advances two parallel workstreams, restoring rsETH's 1.07 ETH backing ratio and unwinding the exploiter's affected positions on Aave Ethereum Core, Aave Arbitrum, and Compound.
To restore rsETH backing, DeFi United will convert its committed ETH into rsETH in tranches before transferring it to the affected RSETH_OFTAdapter lockbox contract on Ethereum. LayerZero and Kelp have implemented additional bridge security measures, with the tranched conversion approach designed to allow those measures to be validated in production. Final execution remains contingent on governance approvals and the completion of definitive agreements.
Clearing the exploiter's eight active positions on Aave Ethereum Core and Arbitrum will require governance proposals on both deployments. The technical sequence involves temporarily adjusting the rsETH oracle price to enable a controlled liquidation, transferring recovered rsETH to a DeFi United multisig, restoring the oracle price, redeeming the rsETH for ETH through Kelp's standard redemption procedure, and applying the resulting ETH to clear the deficits on each market. All configuration adjustments are scoped solely to the recovery and will be reverted upon completion, with no persistent changes to the Aave protocol expected. The plan estimates ~13,000 ETH worth of recoverable funds on Aave. Compound is taking a similar approach, led by its team with DeFi United providing the liquidity, with ~16,776 ETH expected to be recovered.
WETH and rsETH reserves on Ethereum Core, Arbitrum, Base, Mantle, and Linea will remain frozen throughout the recovery period. The final phase involves unpausing and unfreezing rsETH and ETH across affected deployments and restoring temporarily adjusted LTV ratios. The Aave team flagged execution risks, including potential attacker interference that could result in incomplete deficit accrual and require additional liquidation steps, residual bridge risk pending production validation of the new security measures, and the contingency of governance proposals passing and executing correctly on both Ethereum and Arbitrum.
The Arbitrum Security Council has announced emergency action to freeze the 30,766 ETH held in the exploiter's address on Arbitrum One connected to the KelpDAO rsETH exploit. The Security Council stated it acted with input from law enforcement regarding the exploiter's identity, and implemented a technical approach to move the funds without affecting other chain state or Arbitrum users.
As of 3:26 UTC on Apr. 21, the funds have been transferred to an intermediary frozen wallet and are no longer accessible to the original address. Further movement requires action by Arbitrum governance, which the Security Council stated will be coordinated with relevant parties.
The Kelp DAO team has published an incident response statement, stating that its own systems were not involved in building or operating the compromised LayerZero infrastructure. The team states that a subsequent exploit attempt targeting an additional 40,000 rsETH via a falsely verified phantom packet was fully mitigated by Kelp's contract pausing and wallet blacklisting.
Regarding the 1-of-1 DVN configuration, the Kelp team claims this is the default setup documented in LayerZero's quickstart guide and is shipped with any new OFT deployment. Kelp has operated on LayerZero infrastructure since January 2024, and the default configuration was "affirmatively confirmed as appropriate" by LayerZero during Kelp's L2 expansion. The team notes it is working with Aave, LayerZero, and other ecosystem partners on impact assessment, protocol unpausing, and mitigation.
In response to the rsETH exploit, the Compound Foundation has announced that rsETH collateral deposits across eight markets have been paused. Affected markets include Mainnet WETH, USDC, and wstETH, as well as WETH markets on OP, Base, Arbitrum, Unichain, and Linea. Liquidations remained active during the pause, and collateral deposits have since been unpaused. Proposals 568, 569, 570, and 571 have been submitted to adjust risk parameters for full market resumption.
The LayerZero team has released a statement identifying the attack vector on the rsETH exploit as an RPC poisoning attack targeting the LayerZero Labs-operated DVN. According to LayerZero Labs, attackers compromised two independent RPC nodes used by the DVN, replaced their binaries to forge transaction confirmations, and conducted DDoS attacks against uncompromised RPCs to force the DVN to fail over to the poisoned nodes. The LayerZero team attributes the attack to the Lazarus Group (TraderTraitor), a DPRK-linked threat actor, describing this as a "preliminary attribution." No vulnerability was identified in the LayerZero protocol itself.
The attack was limited to rsETH due to KelpDAO's use of LayerZero Labs as its sole verifier in a 1-of-1 DVN configuration. The LayerZero team states that it had previously communicated multi-DVN best practices to KelpDAO before the incident. All affected RPC nodes have been deprecated and replaced, and the LayerZero Labs DVN is now operational. Going forward, the LayerZero Labs DVN will not attest messages from applications using a 1-of-1 DVN configuration. LayerZero is coordinating with law enforcement agencies and Seal911 to track funds.
The LayerZero team has acknowledged the rsETH exploit, stating that "all other applications remain safe." The team has committed to publishing a post-mortem as more information becomes available.
The Kelp DAO team has confirmed that it "identified suspicious cross-chain activity involving rsETH," and has paused rsETH contracts across Ethereum and "several L2s" while it investigates. The team is actively collaborating with the LayerZero and Unichain teams, along with auditors and security experts.
Certik has reported that stolen funds can be traced to 0x5d3919F12bCc35c26Eee5F8226A9bee90c257Ccc (approximately $250 million) and 0xCBb24A6B4DAfaAA1a759A2F413eA0eB6AE1455CC (approximately $2.5 million). Notably, Aave Labs has disclosed that all rsETH markets on Aave v3 and v4 have been frozen, and the team will explore paths to offset the deficit if the protocol accumulates bad debt from the incident.
Security researcher ZachXBT has reported a potential exploit of the KernelDAO Bridge, with the suspected attacker appearing to have extracted ~116,500 rsETH on Ethereum and Arbitrum. The suspicious transaction appears to have originated from the Kelp DAO Unichain OApp.