Lazarus Group-Linked Attackers Drain $292M from KelpDAO Bridge Adapter
A catastrophic vulnerability in KelpDAO's bridge adapter was exploited by attackers on April 18, resulting in the loss of approximately $292 million in rsETH. The attack was made possible due to a single-verifier authentication system, which allowed the attackers to forge a message claiming that a corresponding burn of rsETH had occurred on Unichain.
The bridge adapter relied on LayerZero's internal RPC nodes to authenticate transactions, but the attackers compromised these nodes by replacing legitimate binaries with counterfeit versions. This enabled them to feed fictitious data to the sole Decentralized Verifier Network (DVN), allowing the transaction to be attested as legitimate.
KelpDAO's emergency multisignature team managed to pause the core contracts 46 minutes after the attack began, preventing a follow-up attempt targeting an additional 40,000 rsETH. However, the primary damage was already done, with approximately $292 million in rsETH drained from KelpDAO's LayerZero-powered Omnichain Fungible Token (OFT) adapter.
Preliminary analysis has linked the attack to North Korea's Lazarus Group, specifically its TraderTraitor subgroup. The sophistication of the attack, combining supply chain compromise with a coordinated DDoS campaign, is consistent with the group's playbook.