< Back to all clusters
[TECHNOLOGY] · North Korea · 2 sources

North Korean Lazarus Group Hacks KelpDAO Bridge, Steals $292M in DeFi

On April 18 2026, the Lazarus Group, a North Korean state‑backed hacking unit, compromised two RPC nodes that feed LayerZero’s cross‑chain verifier for KelpDAO’s bridge. By injecting forged messages, the attackers released 116,500 rsETH—a liquid restaking token—worth roughly $292 million. The stolen tokens spread across more than 20 blockchain networks and were promptly used as collateral on major DeFi lending platforms such as Aave, SparkLend and Fluid. Within 48 hours the sector’s total value locked fell by over $13 billion as deposits were withdrawn and markets reacted. Protocols responded by freezing the assets; Aave’s founder collaborated with Lido Finance and EtherFi to cover the shortfall. The exploit underscores the danger of a single‑verifier bridge configuration, prompting LayerZero to cease signing messages for applications that use a 1‑of‑1 verifier and fueling industry calls for multi‑validator designs. The incident is the largest DeFi hack recorded for 2026 and highlights systemic risks in cross‑chain infrastructure.