Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Group Implicated in 0M Kelp DAO Crypto Theft

North Korean Group Implicated in $290M Kelp DAO Crypto Theft

Posted on April 21, 2026 By CWS

A notorious cybercrime group allegedly tied to North Korea, known as the Lazarus Group, is under scrutiny for a massive cryptocurrency theft from the decentralized finance protocol, Kelp DAO. The incident, which targeted a substantial sum of $290 million in digital assets, unfolded with alarming precision.

Details of the Heist

The breach took place on a Sunday evening, at precisely 17:35 UTC, when the attackers managed to execute a malicious command. This action resulted in the unauthorized extraction of 116,500 restaked Ether (rsETH), equivalent to approximately $292 million. In response, Kelp DAO swiftly paused pertinent contracts and blacklisted the attackers’ wallets. This proactive measure successfully thwarted a subsequent attempt to seize an additional 40,000 rsETH, valued at around $95 million.

Kelp DAO operates as a liquid restaking protocol, where user-deposited Ether is funneled through the EigenLayer restaking system to generate extra rewards, whereby rsETH is issued. The attackers exploited a vulnerability in the protocol’s ‘1-of-1 verifier configuration’ to disrupt the verification process, leading to the unauthorized fund transfer.

Technical Vulnerabilities Exploited

The attackers focused on LayerZero, a cross-chain messaging infrastructure essential for transmitting verified blockchain instructions. LayerZero’s Decentralized Verifier Network (DVN) depends on multiple Remote Procedure Calls (RPCs) to verify cross-chain commands’ integrity. The cybercriminals successfully compromised two of these RPCs, paving the way for an RPC-spoofing attack.

This attack capitalized on a custom payload designed to craft a forged message to the DVN with minimal alerts. Subsequently, the attackers launched a Distributed Denial-of-Service (DDoS) attack on the remaining RPCs, causing a failover to the compromised nodes and allowing their fraudulent commands to be accepted.

Responses and Implications

LayerZero attributes this sophisticated attack to a subgroup named TraderTraitor, part of the infamous Lazarus Group, notorious for multiple cryptocurrency heists in recent years. According to LayerZero, the incident could have been avoided if Kelp DAO had adopted a multi-DVN setup, which is a recommended industry standard.

In a statement, LayerZero noted that they had previously advised Kelp DAO on diversifying their DVN configuration. Kelp DAO, however, points fingers at LayerZero, arguing that their systems were not managing the targeted infrastructure and that the single-DVN setup was documented by LayerZero as appropriate.

In the aftermath, Kelp DAO has prioritized measures to prevent further contagion across the DeFi ecosystem. Partners like the Arbitrum Security Council promptly froze assets linked to the heist. Nevertheless, the ramifications are extensive, with decentralized liquidity protocol Aave experiencing a significant decrease in total value by nearly $8 billion.

Binance reported that the stolen funds were deposited into Aave v3 as collateral, leading to the borrowing of wrapped Ether and creating a $195 million debt on Aave. The rush of users withdrawing assets led to full utilization of Aave v3 lending pools, immobilizing over $5.1 billion in stablecoins.

As the crypto community grapples with the fallout, this incident underscores the critical need for robust security measures and cross-chain communication protocols to safeguard digital assets.

Security Week News Tags:blockchain security, crypto theft, Cryptocurrency, Cyberattack, DeFi, Ethereum, Kelp DAO, LayerZero, Lazarus Group, North Korea

Post navigation

Previous Post: SideWinder Targets Government Emails with Fake PDF Viewer
Next Post: Understanding Identity-Based Cyber Attacks and Defense

Related Posts

Defend Against Identity Threats: Join Our Webinar Defend Against Identity Threats: Join Our Webinar Security Week News
Private Sector Vital in Cybersecurity Battle Private Sector Vital in Cybersecurity Battle Security Week News
Google Patches Gemini AI Hacks Involving Poisoned Logs, Search Results Google Patches Gemini AI Hacks Involving Poisoned Logs, Search Results Security Week News
Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza Security Week News
Armis Raises 5 Million in Pre-IPO Funding Round at .1 Billion Valuation Armis Raises $435 Million in Pre-IPO Funding Round at $6.1 Billion Valuation Security Week News
Minnesota Activates National Guard in Response to Cyberattack Minnesota Activates National Guard in Response to Cyberattack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Progress Releases Vital Patches for MOVEit and LoadMaster
  • Boosting MTTR: Key Strategies of Advanced SOCs
  • Gentlemen RaaS Targets Multiple OS with Advanced Ransomware
  • Security Flaws in Perforce Servers Risk Sensitive Data
  • NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Progress Releases Vital Patches for MOVEit and LoadMaster
  • Boosting MTTR: Key Strategies of Advanced SOCs
  • Gentlemen RaaS Targets Multiple OS with Advanced Ransomware
  • Security Flaws in Perforce Servers Risk Sensitive Data
  • NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark