• bitcoinBitcoin (BTC) $ 80,651.00
  • ethereumEthereum (ETH) $ 2,323.20
  • tetherTether (USDT) $ 0.999797
  • xrpXRP (XRP) $ 1.41
  • bnbBNB (BNB) $ 646.19
  • usd-coinUSDC (USDC) $ 0.999938
  • solanaSolana (SOL) $ 92.89
  • tronTRON (TRX) $ 0.350223
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.108162
  • whitebitWhiteBIT Coin (WBT) $ 59.46
  • usdsUSDS (USDS) $ 0.999783
  • hyperliquidHyperliquid (HYPE) $ 42.64
  • zcashZcash (ZEC) $ 598.99
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.269593
  • leo-tokenLEO Token (LEO) $ 10.32
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 449.66
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 407.92
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 10.31
  • the-open-networkToncoin (TON) $ 2.43
  • canton-networkCanton (CC) $ 0.155693
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.161601
  • litecoinLitecoin (LTC) $ 57.78
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 0.999385
  • daiDai (DAI) $ 0.999774
  • memecoreMemeCore (M) $ 3.39
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • suiSui (SUI) $ 1.07
  • avalanche-2Avalanche (AVAX) $ 9.88
  • hedera-hashgraphHedera (HBAR) $ 0.092601
  • wethWETH (WETH) $ 2,268.37
  • ethena-usdeEthena USDe (USDE) $ 0.999487
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007415
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999670
  • crypto-com-chainCronos (CRO) $ 0.070585
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 310.76
  • tether-goldTether Gold (XAUT) $ 4,706.98
  • global-dollarGlobal Dollar (USDG) $ 0.999955
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • uniswapUniswap (UNI) $ 3.72
  • mantleMantle (MNT) $ 0.680241
  • polkadotPolkadot (DOT) $ 1.33
  • pax-goldPAX Gold (PAXG) $ 4,708.79
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.070009
  • ondo-financeOndo (ONDO) $ 0.411614
  • nearNEAR Protocol (NEAR) $ 1.55
  • internet-computerInternet Computer (ICP) $ 3.55
  • okbOKB (OKB) $ 87.47
  • skySky (SKY) $ 0.079088
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • pi-networkPi Network (PI) $ 0.173374
  • aster-2Aster (ASTER) $ 0.698095
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • falcon-financeFalcon USD (USDF) $ 0.998160
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pepePepe (PEPE) $ 0.000004
  • ripple-usdRipple USD (RLUSD) $ 0.999861
  • ethereum-classicEthereum Classic (ETC) $ 9.59
  • bitget-tokenBitget Token (BGB) $ 2.12
  • usddUSDD (USDD) $ 0.999912
  • aaveAave (AAVE) $ 95.28
  • morphoMorpho (MORPHO) $ 2.12
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bfusdBFUSD (BFUSD) $ 0.999100
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ethenaEthena (ENA) $ 0.127347
  • algorandAlgorand (ALGO) $ 0.127143
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • kucoin-sharesKuCoin (KCS) $ 8.43
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.100726
  • quant-networkQuant (QNT) $ 72.81
  • render-tokenRender (RENDER) $ 1.98
  • united-stablesUnited Stables (U) $ 0.999116
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • kaspaKaspa (KAS) $ 0.037308
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.08
  • cosmosCosmos Hub (ATOM) $ 1.90
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.77
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • filecoinFilecoin (FIL) $ 1.19
  • nexoNEXO (NEXO) $ 0.912600
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • siren-2Siren (SIREN) $ 1.24
  • worldcoin-wldWorldcoin (WLD) $ 0.265937
  • wbnbWrapped BNB (WBNB) $ 759.61
  • aptosAptos (APT) $ 1.09
  • arbitrumArbitrum (ARB) $ 0.140001
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • gatechain-tokenGate (GT) $ 7.47
  • jupiter-exchange-solanaJupiter (JUP) $ 0.243127
  • stable-2​​Stable (STABLE) $ 0.034030
  • pump-funPump.fun (PUMP) $ 0.002134
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • justJUST (JST) $ 0.083448
  • flare-networksFlare (FLR) $ 0.008302
  • venice-tokenVenice Token (VVV) $ 15.39
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010504
  • vechainVeChain (VET) $ 0.007531
  • bonkBonk (BONK) $ 0.000007
  • usdtbUSDtb (USDTB) $ 0.999048
  • dashDash (DASH) $ 49.05
  • skyaiSkyAI (SKYAI) $ 0.614887
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • beldexBeldex (BDX) $ 0.079855
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ousgOUSG (OUSG) $ 115.18
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.030127
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.892615
  • ghoGHO (GHO) $ 0.999669
  • clbtcclBTC (CLBTC) $ 76,920.00
  • hash-2Provenance Blockchain (HASH) $ 0.010891
  • official-trumpOfficial Trump (TRUMP) $ 2.44
  • dexeDeXe (DEXE) $ 11.94
  • usual-usdUsual USD (USD0) $ 0.998214
  • midnight-3Midnight (NIGHT) $ 0.032541
  • yldsYLDS (YLDS) $ 0.999955
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.230274
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000093
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • a7a5A7A5 (A7A5) $ 0.012887
  • tbtctBTC (TBTC) $ 70,942.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.54
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • true-usdTrueUSD (TUSD) $ 0.999511
  • blockstackStacks (STX) $ 0.261753
  • aerodrome-financeAerodrome Finance (AERO) $ 0.499402
  • sei-networkSei (SEI) $ 0.068787
  • chilizChiliz (CHZ) $ 0.044340
  • euro-coinEURC (EURC) $ 1.18
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • edgexedgeX (EDGE) $ 1.28
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • spx6900SPX6900 (SPX) $ 0.461492
  • adi-tokenADI (ADI) $ 4.03
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • usdgoUSDGO (USDGO) $ 1.00
  • tezosTezos (XTZ) $ 0.383277
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • injective-protocolInjective (INJ) $ 4.12
  • monadMonad (MON) $ 0.034280
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999378
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • kite-2Kite (KITE) $ 0.174167
  • celestiaCelestia (TIA) $ 0.432825
  • sun-tokenSun Token (SUN) $ 0.020281
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.385358
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • usxUSX (USX) $ 0.999705
  • megausdMegaUSD (USDM) $ 0.999340
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • curve-dao-tokenCurve DAO (CRV) $ 0.248371
  • ether-fiEther.fi (ETHFI) $ 0.441844
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • humanityHumanity (H) $ 0.200883
  • build-onBUILDon (B) $ 0.368322
  • layerzeroLayerZero (ZRO) $ 1.44
  • labLAB (LAB) $ 4.71
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • jasmycoinJasmyCoin (JASMY) $ 0.007180
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • kinesis-goldKinesis Gold (KAU) $ 147.60
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • apxusdapxUSD (APXUSD) $ 0.999946
  • gnosisGnosis (GNO) $ 132.33
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • optimismOptimism (OP) $ 0.161316
  • flokiFLOKI (FLOKI) $ 0.000036
  • doublezeroDoubleZero (2Z) $ 0.098321
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • pendlePendle (PENDLE) $ 2.01
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • conflux-tokenConflux (CFX) $ 0.064875
  • decredDecred (DCR) $ 19.29
  • zebec-networkZebec Network (ZBCN) $ 0.003401
  • lido-daoLido DAO (LDO) $ 0.392103
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Kelp claims that LayerZero approved the setup it blamed for $292 million bridge hack

0 0


Kelp DAO claims that LayerZero personnel approved the 1-of-1 verifier setup, a decision LayerZero has since cited as the reason a North Korea-linked attacker drained roughly $292 million from Kelp’s rsETH bridge.

The claim runs counter to LayerZero’s April 19 postmortem, which said Kelp’s rsETH application relied on LayerZero Labs as its sole verifier and that the setup “directly contradicts” LayerZero’s recommended multi-DVN model.

Kelp’s memo says LayerZero personnel reviewed its configurations for over 2.5 years and in eight integration discussions, without warning that a 1-of-1 setup posed a material security risk.

The memo, titled “Setting the Record Straight Around the LayerZero Bridge Hack,” includes screenshots of Telegram exchanges that document LayerZero’s awareness and lack of objection to Kelp’s verifier setup.

One screenshot shows a LayerZero team member saying: “No problem on using defaults either — just tagging [redacted] here since he mentioned you may have wanted to use a custom DVN setup for verifying messages, but will leave that to your team!” Kelp says the “defaults” referenced in the exchange were the 1-of-1 LayerZero Labs DVN configuration later cited by LayerZero as the application-level setup that enabled the exploit.

CoinDesk could not independently authenticate the screenshot.

LayerZero’s templates

Kelp also points to LayerZero’s bug bounty scope, OFT Quickstart and developer examples as evidence that LayerZero treated verifier-network choices as application-level configuration while showing builders a one-DVN setup.

LayerZero’s published bug bounty scope on Immunefi excludes from rewards “impacts to OApps themselves as a result of their own misconfiguration,” including verifier networks and executors.

The LayerZero OFT Quickstart and the official OFT example configuration on GitHub show LayerZero Labs as the required DVN, with no optional DVN set.

Kelp’s memo cites an April 19 post from Spearbit security researcher Sujith Somraaj, in which Somraaj said he had submitted a bug bounty report describing the same attack pattern and that LayerZero rejected it.

“My bug bounty: not a vuln, requires all DVNs,” Somraaj wrote on X. “Their deployment: removes the ‘all’ part. Hackers: collects $295M bounty instead.” Somraaj is a prior LayerZero auditor, according to his Cantina profile.

Kelp moves to Chainlink

Kelp also said it is moving rsETH off LayerZero to Chainlink’s Cross-Chain Interoperability Protocol. The shift moves rsETH from LayerZero’s OFT standard to Chainlink’s Cross-Chain Token standard.

The exploit drained 116,500 rsETH, worth roughly $292 million, from Kelp’s LayerZero-powered bridge. Two additional forged transactions totaling more than $100 million were signed and processed by the LayerZero Labs DVN before Kelp paused its contracts, the protocol said.

LayerZero said attackers are likely linked to North Korea’s Lazarus Group, who accessed the list of RPCs used by the LayerZero Labs DVN, compromised two RPC nodes and swapped out the binaries running on them.

The attackers then launched a DDoS attack against uncompromised RPC nodes, forcing a failover to the poisoned ones. LayerZero said the DVN then confirmed transactions that had not occurred.

Kelp argues the 1-of-1 setup was widespread. CoinGecko, citing Dune Analytics data, said 47% of roughly 2,665 active LayerZero OApp contracts ran a 1-of-1 DVN configuration over a 90-day period ending around April 22, with more than $4.5 billion in associated market value exposed to the same class of risk.

LayerZero’s postmortem said the protocol “functioned exactly as intended.” The company said it would no longer sign messages for any application running a 1-of-1 configuration, a policy change that took effect after the hack.

Kelp alleges that its team had to flag the exploit to LayerZero rather than the other way around, raising questions about LayerZero’s monitoring.

The memo also alleges substantial overlap in addresses granted ADMIN_ROLE on both the LayerZero Labs DVN and the Nethermind DVN, listing ten on April 8, 2026 and five additional on February 6, 2025. CoinDesk has not independently verified the onchain claim.

LayerZero did not respond to a request for comment by publication.

On at least two integrated chains, Dinari and Skale, the LayerZero Labs DVN is still listed as the only available attestor, according to the documentation.



Source link

Leave A Reply

Your email address will not be published.