LayerZero Labs released a report on the KelpDAO attack incident, confirming that the KelpDAO rsETH cross-chain bridge built on its cross-chain communication protocol was attacked, resulting in the theft of approximately 116,500 rsETH (about $292 million). Several security agencies, including Mandiant, CrowdStrike, and independent researchers, attributed the attack to the North Korean-related hacker group TraderTraitor (UNC4899).
The report indicates that the attack began on March 6, 2026, when the attackers used social engineering techniques to compromise a LayerZero developer account, obtain session keys, and infiltrate the RPC cloud environment, further contaminating internal RPC node data and manipulating return results to deceive monitoring systems and the decentralized verification network (DVN).
LayerZero Labs officially announced that it will adjust its security strategy, including no longer allowing its DVN to act as the sole signer in a single validation configuration, while also rebuilding the affected cloud infrastructure and introducing short-term credentials, instant permission upgrades, and multi-party approval mechanisms to enhance security.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























