LayerZero Team Accused North Korea of Hacking KelpDAO

LayerZero Team Accused North Korea of Hacking KelpDAO

Behind the attack on the liquid restaking protocol KelpDAO, which saw attackers siphon off roughly $290 million-$292 million, is likely the North Korean hacking group Lazarus Group — specifically its TraderTraitor subunit, which is often linked to state-backed cyberattacks — according to a statement from LayerZero.

The incident, which occurred on April 18, 2026, has already triggered a chain reaction across the DeFi sector: mass withdrawals from Aave, a drop in the market’s total value locked, and renewed concerns about the security of crosschain infrastructure.

How the Hack Happened and Why Responsibility Is Partly Placed on KelpDAO

According to LayerZero, the attackers carried out a sophisticated attack on the RPC infrastructure used by the DVN node to validate transactions.

The hackers:

  • Compromised two RPC nodes
  • Replaced the binary files that ran the op-geth nodes
  • Carried out RPC request spoofing attacks
  • Simultaneously launched a DDoS attack on unaffected nodes
  • Forced the system to switch to “poisoned” backup RPCs

As a result, the DVN confirmed transactions that never actually happened.

LayerZero emphasized that the compromise did not spread to other assets.

At the same time, the crypto community sharply criticized KelpDAO for choosing a weak architecture without redundant verification. One user, under the handle hendricks, noted that the risk of the 1/1 DVN model had been raised as far back as 15 months ago on the Aave governance forum:

“This wasn’t bad luck — this was a conscious choice. Extremely suspicious.”

Criticism was also directed at LayerZero itself. User Bradly (CryptPlayer) noted:

“It looks like you shift all responsibility to KelpDAO, but actually you share it.”

A similar view was voiced by StarkWare CISO Haim Krasniker, who pointed out a contradiction in the failover mechanism:

“Once that DDoS happened, it should not default to Internal RPCs that are solely controlled by LZ.”

Domino Effect: Aave, Decline in TVL, and Pressure on ETH Liquidity

The most serious secondary hit landed on Aave. After the hack, the rsETH asset was urgently frozen on Aave V3 and V4. This was announced by protocol founder Stani Kulechov.

According to market estimates, the incident has already caused Aave’s TVL to drop to approximately $18 billion due to fears of bad debt.

Analyst Anndy Lian noted that the direct debt of $177 million accounts for just 0.65% of Aave’s total value locked (TVL), estimated at around $27.3 billion, but the biggest pressure is being felt by liquidity providers on Ethereum.

In his words:

“It is currently facing its most severe existential test since inception.”

Recall that the KelpDAO hack was only part of a broader cybersecurity crisis in the crypto industry. According to CertiK, in March 2026 alone, 46 attacks were recorded, the highest figure since November 2024.

In addition, the market has already endured:

  • The hack of Drift for about $280 million
  • An incident involving Stabble due to the possible involvement of a developer linked to North Korea
  • The hack of Hyperbridge, which triggered Polkadot (DOT) to drop to $1.15 after the illicit minting of 1 billion DOT

 

Source: https://incrypted.com/en/layerzero-team-accused-north-korea-of-hacking-kelpdao/

 

 

 

Anndy Lian is an early blockchain adopter and experienced serial entrepreneur who is known for his work in the government sector. He is a best selling book author- “NFT: From Zero to Hero” and “Blockchain Revolution 2030”.

Currently, he is appointed as the Chief Digital Advisor at Mongolia Productivity Organization, championing national digitization. Prior to his current appointments, he was the Chairman of BigONE Exchange, a global top 30 ranked crypto spot exchange and was also the Advisory Board Member for Hyundai DAC, the blockchain arm of South Korea’s largest car manufacturer Hyundai Motor Group. Lian played a pivotal role as the Blockchain Advisor for Asian Productivity Organisation (APO), an intergovernmental organization committed to improving productivity in the Asia-Pacific region.

An avid supporter of incubating start-ups, Anndy has also been a private investor for the past eight years. With a growth investment mindset, Anndy strategically demonstrates this in the companies he chooses to be involved with. He believes that what he is doing through blockchain technology currently will revolutionise and redefine traditional businesses. He also believes that the blockchain industry has to be “redecentralised”.

j j j

Binance Team Rebuffs Any KYC Data Leaks On Dark Web

Binance Team Rebuffs Any KYC Data Leaks On Dark Web

In the latest development, a github hack leak revealed that Binance’s users’ data might be facing some threats with a large amount of KYC information now available on the dark web platforms. This led to a major buzz in the market forcing the Binance team to respond.

Binance Security Team Assures Saftey

In response to recent concerns raised by users, Binance’s security team has diligently evaluated the situation, as is customary for all potential threats. The team has conclusively confirmed that there is no indication of a leak from Binance systems, and user accounts remain secure.

Binance assures its users that their accounts are safeguarded against various potential risks. The exchange has incorporated multi-layered security measures in place, including Multi-Factor Authentication (MFA), biometrics, and authenticators.

Binance extends its appreciation to users who bring potential bugs and security issues to their attention. The proactive reporting also allows the platform to thoroughly investigate any concerns and, where necessary, take prompt action to enhance user protection. Furthermore, as the cryptocurrency landscape evolves, Binance said that it remains committed to maintaining the highest standards of security for its user base.

Last week, Binance also initiated quick action after freezing $4.2 million worth of XRP, stolen from co-founder Chris Larsen’s account. Binance CEO Richard Teng has affirmed his support for Ripple’s investigations and commitment to closely monitoring the external wallets of the exploiter.

Addressing the Rising Crypto Scams

Last week, Binance raised alarms about a troubling resurgence in cryptocurrency scams exploiting the current market conditions. Notably, scammers are exploiting the identities of industry figures such as Yi He, Binance’s co-founder, and Anndy Lian, a prominent blockchain author.

Impersonators have created deceptive LinkedIn profiles using Yi He’s identity to approach potential victims, offering token listings on Binance in exchange for significant payments. Yi He also emphasized her minimal involvement with LinkedIn and non-participation in listing discussions, urging caution against false claims of insider connections.

Additionally, Anndy Lian disclosed WhatsApp scams where fraudsters impersonate Binance staff, enticing individuals to join cryptocurrency groups with false promises of passive income.

 

Source: https://coingape.com/binance-team-rebuffs-any-kyc-data-leaks-on-dark-web/?utm_source=sidebartabnews

Anndy Lian is an early blockchain adopter and experienced serial entrepreneur who is known for his work in the government sector. He is a best selling book author- “NFT: From Zero to Hero” and “Blockchain Revolution 2030”.

Currently, he is appointed as the Chief Digital Advisor at Mongolia Productivity Organization, championing national digitization. Prior to his current appointments, he was the Chairman of BigONE Exchange, a global top 30 ranked crypto spot exchange and was also the Advisory Board Member for Hyundai DAC, the blockchain arm of South Korea’s largest car manufacturer Hyundai Motor Group. Lian played a pivotal role as the Blockchain Advisor for Asian Productivity Organisation (APO), an intergovernmental organization committed to improving productivity in the Asia-Pacific region.

An avid supporter of incubating start-ups, Anndy has also been a private investor for the past eight years. With a growth investment mindset, Anndy strategically demonstrates this in the companies he chooses to be involved with. He believes that what he is doing through blockchain technology currently will revolutionise and redefine traditional businesses. He also believes that the blockchain industry has to be “redecentralised”.

j j j