• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

LayerZero Under Fire For KelpDAO $290M Exploit Response

April 21, 2026
in Bitcoin
Reading Time: 5min read
0 0
A A
0
LayerZero Under Fire For KelpDAO $290M Exploit Response
0
SHARES
0
VIEWS
ShareShareShareShareShare

LayerZero is facing heavy criticism for its response to the recent $290 million KelpDAO exploit after the omnichain interoperability protocol blamed Kelp’s 1-of-1 verifier configuration for the incident.

Related Reading

LayerZero Blames KelpDAO For $290M Exploit

Over the weekend, liquid restaking protocol KelpDAO was the victim of an attack that drained over $290 million in rsETH from the project after malicious actors exploited a weakness in the protocol’s LayerZero-powered bridge.

Two days later, LayerZero addressed the incident, which became the largest DeFi hack of 2026, just weeks after Drift Protocol’s $285 million exploit shocked the industry.

LayerZero attributed the “highly sophisticated attack” to North Korea’s Lazarus Group, claiming that it was a crypto infrastructure attack rather than a protocol exploit, and affirming that “there is zero contagion to any other cross-chain assets or applications.”

LayerZero’s post-mortem. Source: X

They explained that the protocol is built on a “foundation of modular, application-configurable security,” using Decentralized Verifier Networks (DVNs), independent entities responsible for verifying the integrity of cross-chain messages.

The malicious actors allegedly poisoned downstream RPC infrastructure by “compromising a quorum of the RPCs the LayerZero Labs DVN relied upon to verify transactions.”

Per the post, the attackers swapped binaries for a custom payload to forge messages and used DDoS attacks to force failover to the poisoned nodes, triggering the DVN into confirming fake transactions.

Based on this, LayerZero placed responsibility on KelpDAO for using a 1-of-1 verifier configuration instead of the multi-DVN recommendations: “This incident was isolated entirely to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup.”

Crypto Community Criticizes ‘Lack Of Accountability’

The crypto community reacted to the post-mortem, sharing its concerns about LayerZero’s response and criticizing the protocol for placing all responsibility only on Kelp’s security setup.

“Imagine building a bridge and vehicles pays to cross, the bridge collapsed and you said it’s their fault for crossing the bridge. A classic clownery act from Bunch of clowns with zero accountability,” X user Saint wrote.

Others questioned why LayerZero included a “1-of-1” configuration if the purpose of a DVN is customizable/modular security. “If the system allows this option, it’s not the fault of the customer who chose it—it’s a fundamental design flaw by the system that permitted it,” user Ditto wrote.

“At the end of the day, the fact remains that the DVN RPC was compromised. DVN is a LayerZero product, and they are the ones who sold it to these teams,” he continued.

Similarly, Chainlink community manager Zach Rynes accused the protocol of deflecting responsibility for the compromise of their own DVN node.

He also criticized them for “throwing KelpDAO under the bus” for trusting LayerZero Labs’ setup that they “willingly support and only blocked after getting hacked, all while claiming everything worked as designed.”

Meanwhile, Yearn Finance core team developer Artem K noted on X that the attack was described as a compromise of an RPC node and RPC poisoning, but that their own infrastructure is what was compromised. “Given it doesn’t say how the breach has occurred, I wouldn’t rush re-enabling the bridges,” he added.

Wrong Diagnosis, Wrong Fix?

Analyst The Smart Ape also claims that LayerZero made the wrong diagnosis and offered the wrong solution. Notably, the protocol’s post-mortem suggested migrating all applications with 1-of-1 DVN configurations to multi-DVN setups to prevent similar attacks.

However, the analyst pointed out that multi-verifiers won’t stop the next multi-million-dollar attack, asserting that they could fail as all DVNs read chain states from the same handful of RPC providers, which are mostly clustered on AWS or GCP.

If five “independent” DVNs read from the same three RPC providers, an attacker who poisons those three RPCs will poison all five verifiers simultaneously. “If all your verifiers get fooled in the same way at the same time, the math collapses back to 1-of-1. Five clones are not five witnesses,” he added.

Related Reading

To solve this, the analyst suggested that every verifier runs its own full node on different client software, hosted on different cloud providers, maintained by different ops teams, peered with different subsets of the Ethereum network.

“The fix isn’t multi-anything. The fix is that verifiers should attest to their own substrate, not just to chain state. until you can audit a DVN’s upstream topology, which RPC providers, which client software, which clouds, which regions, ‘M-of-N secured’ is marketing copy for a property that hasn’t actually been built. Lazarus didn’t break cryptography on April 18. They broke three servers,” he concluded.

LayerZero, TOTAL
The total crypto market capitalization is at $2.54 trillion in the one-week chart. Source: TOTAL on TradingView

Featured Image from Unsplash.com, Chart from TradingView.com

Credit: Source link

ShareTweetSendPinShare
Previous Post

North Korea-Linked Hackers Escalate Crypto Attacks With $500M+ Two-Week Haul

Next Post

Bitcoin Price Prediction: Blackrock Big Bitcoin Bet

Next Post
Bitcoin Price Prediction: Blackrock Big Bitcoin Bet

Bitcoin Price Prediction: Blackrock Big Bitcoin Bet

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You might also like

SUI And USDC Now Power Real-World Transactions On RedotPay

SUI And USDC Now Power Real-World Transactions On RedotPay

April 22, 2026
Anthropic Launches Claude 3.5 Sonnet Android App with Advanced AI Features

Anthropic Survey Reveals AI Job Displacement Fears Amid Productivity Gains

April 22, 2026
Former Treasury Chief Warns Bond Market Crash Could Hit Crypto Outlook

Former Treasury Chief Warns Bond Market Crash Could Hit Crypto Outlook

April 19, 2026
Bitcoin’s Quantum Defense Plan Faces Criticism From Cardano Founder

Bitcoin’s Quantum Defense Plan Faces Criticism From Cardano Founder

April 17, 2026
Onramp Launches New Bitcoin Finance Platform for BTC-Native Services

Onramp Launches New Bitcoin Finance Platform for BTC-Native Services

April 22, 2026
Cardano Crypto Holds $0.24 as ADA’s Volume Jumps 48%: Recovery Ahead?

Cardano Crypto Holds $0.24 as ADA’s Volume Jumps 48%: Recovery Ahead?

April 21, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

US Government Runs a Bitcoin Node, Admiral Says, But Is Not Mining BTC

US Government Runs a Bitcoin Node, Admiral Says, But Is Not Mining BTC

April 23, 2026
DeFi Just Lost $15 Billion in Three Days. Something Deeper Than a Hack Is Behind It

DeFi Just Lost $15 Billion in Three Days. Something Deeper Than a Hack Is Behind It

April 23, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.