- LayerZero confirmed that Kelp’s insistence on a single-DVN setup led to its over $292 million hack.
In case you missed it, the largest decentralized finance (DeFi) exploit in 2026 just happened over the weekend. At the center of the $292 million to $294 million hack is KelpDAO, a liquid staking protocol.
LayerZero (ZRO), an omnichain interoperability protocol powering Kelp, released its own report about the incident on Monday. It revealed more details regarding the nature of the attack and Kelp’s lapses, which heavily contributed to the vulnerability in its protocol.
Nature of the KelpDAO Attack
LayerZero Labs attributed the high-profile heist to the Lazarus Group, a state-sponsored hacking outfit in North Korea. It traced the activity from a pseudonymous actor, TraderTraitor.
According to the investigation, the culprit poisoned the downstream RPC (Remote Procedure Call), a communication protocol utilized by the LayerZero DVN (Decentralized Verifier Network). The hacker tricked the system by injecting a fraudulent message into its pipeline to verify a massive withdrawal that had never actually occurred on the source chain.
LayerZero Highlights Kelp’s Lapses
LayerZero claimed its protocol is built on a modular, application-configurable security. Hence, platforms like Kelp can adjust their specifications to meet their requirements.
However, the foundation always recommended that integrators of its tools adhere to industry best practices. It advised against relying on a single security configuration.
Confirming the suspicions of David Schwartz, CTO Emeritus of Ripple, LayerZero found that Kelp had failed to implement its suggested multi-DVN configuration for diversity and redundancy. Instead, the hacked protocol only employed a single-DVN model for its Restaked ETH (rsETH) specification.
LayerZero highlighted that it initially raised concerns about Kelp’s 1/1 DVN configuration. Other parties also supposedly cautioned the platform about it.
Ignoring the warnings, Kelp continued to operate in a single-point-of-failure configuration. It meant it had no independent verifier to catch and rejected a forged message. Unfortunately, the attacker exploited the same vulnerability last weekend to manipulate the liquid staking protocol’s system.
Had Kelp heeded the calls for a multi-DVN setup, LayerZero believes the multiple independent DVNs within the consensus mechanism could have easily thwarted the hacker, even if the perpetrator compromised a single DVN.
Meanwhile, Schwartz stated that the report showed a more sophisticated attack than what he expected. Nonetheless, he primarily credited the hacker’s success to Kelp’s “laziness.”
LayerZero Denies Contagion Across Other Chains
LayerZero ensured the public that it had already purged and replaced the compromised RPC nodes. Furthermore, it noted that its DVN is now live and there is zero contagion on other cross-chain assets and applications.







