LayerZero Reports KelpDAO Attack: North Korean-Linked Hackers Steal 116,500 rsETH ($292M) on April 18

ZRO1.78%

According to LayerZero Labs' incident report, on April 18, rsETH cross-chain bridge was attacked, resulting in 116,500 rsETH (approximately $292 million) stolen. Mandiant, CrowdStrike, and independent researchers attributed the attack to North Korean-linked hacker group TraderTraitor (UNC4899).

The attack began on March 6 via social engineering targeting LayerZero developer accounts. Attackers obtained session keys, infiltrated RPC cloud environments, and poisoned internal RPC node data to generate fraudulent cross-chain proofs. They then launched denial-of-service attacks against external RPC providers, forcing the verification system to rely on compromised nodes. The core vulnerability: the affected application used a single-verifier configuration, allowing asset release after receiving just one valid signature.

LayerZero Labs stated it will adjust security strategies by prohibiting its DVN from serving as the sole signer in single-verifier setups, rebuilding affected cloud infrastructure, and implementing short-lived credentials, immediate privilege escalation, and multi-approval mechanisms. zeroShadow and law enforcement have initiated investigation and asset tracking.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments