Last month, LayerZero released a report regarding the KelpDAO attack, one of the biggest hacking attacks in the DeFi world. Continue Reading: LayerZero (ZRO),Last month, LayerZero released a report regarding the KelpDAO attack, one of the biggest hacking attacks in the DeFi world. Continue Reading: LayerZero (ZRO),

LayerZero (ZRO), Which Was Blamed for the KelpDAO Hack Last Month, Has Released Its First Report on the Incident

2026/05/21 03:27
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

LayerZero has published its comprehensive incident report on the massive April attack on KelpDAO’s rsETH bridge.

According to the report, approximately 116,500 rsETH were stolen in the attack that took place on April 18. The total value of the stolen assets is estimated to be around $292 million. Multiple security companies believe that the North Korea-linked hacker group TraderTraitor (UNC4899) was behind the attack.

According to the company’s statement, the attack did not directly target the LayerZero protocol or other OApps. It only affected the rsETH bridge, which has a single validator configuration for KelpDAO. LayerZero stated that the incident was rooted in an advanced social engineering operation carried out at the infrastructure level.

According to the report, attackers obtained LayerZero Labs developers’ session keys through social engineering methods as of March 6. They then infiltrated the company’s RPC cloud environment and manipulated internal RPC nodes, deploying memory patches. These nodes continued to return normal data to monitoring tools, but provided altered blockchain state information to LayerZero’s DVN (Decentralized Validator Network) system.

Related News: Bloomberg Analyst Says There Is Strong Demand for a Spot ETF for a Certain Altcoin

It was also stated that the attackers launched DoS attacks against external RPC providers, thus making the DVN system dependent solely on the compromised internal nodes. This process ultimately generated valid evidence for forged cross-chain messages, and because KelpDAO’s single validator configuration allowed it, the rsETH contract accepted this evidence, releasing the assets.

Following the incident, LayerZero Labs announced significant changes to its security architecture. The company stated that it has mandated minimum security configurations for channels using DVN and will no longer provide signatures as the sole validator. Furthermore, it was noted that the affected infrastructure has been completely rebuilt based on a zero-trust architecture, and instant privilege escalation mechanisms have been implemented.

LayerZero added that they continue to strengthen their security configurations together with their ecosystem partners and are collaborating with law enforcement and security companies to investigate the attack, identify the perpetrator, and track fund movements.

*This is not investment advice.

Continue Reading: LayerZero (ZRO), Which Was Blamed for the KelpDAO Hack Last Month, Has Released Its First Report on the Incident

시장 기회
LayerZero 로고
LayerZero 가격(ZRO)
$1.146
$1.146$1.146
+1.68%
USD
LayerZero (ZRO) 실시간 가격 차트

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw