Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Group Implicated in 0M Kelp DAO Crypto Theft

North Korean Group Implicated in $290M Kelp DAO Crypto Theft

Posted on April 21, 2026 By CWS

A notorious cybercrime group allegedly tied to North Korea, known as the Lazarus Group, is under scrutiny for a massive cryptocurrency theft from the decentralized finance protocol, Kelp DAO. The incident, which targeted a substantial sum of $290 million in digital assets, unfolded with alarming precision.

Details of the Heist

The breach took place on a Sunday evening, at precisely 17:35 UTC, when the attackers managed to execute a malicious command. This action resulted in the unauthorized extraction of 116,500 restaked Ether (rsETH), equivalent to approximately $292 million. In response, Kelp DAO swiftly paused pertinent contracts and blacklisted the attackers’ wallets. This proactive measure successfully thwarted a subsequent attempt to seize an additional 40,000 rsETH, valued at around $95 million.

Kelp DAO operates as a liquid restaking protocol, where user-deposited Ether is funneled through the EigenLayer restaking system to generate extra rewards, whereby rsETH is issued. The attackers exploited a vulnerability in the protocol’s ‘1-of-1 verifier configuration’ to disrupt the verification process, leading to the unauthorized fund transfer.

Technical Vulnerabilities Exploited

The attackers focused on LayerZero, a cross-chain messaging infrastructure essential for transmitting verified blockchain instructions. LayerZero’s Decentralized Verifier Network (DVN) depends on multiple Remote Procedure Calls (RPCs) to verify cross-chain commands’ integrity. The cybercriminals successfully compromised two of these RPCs, paving the way for an RPC-spoofing attack.

This attack capitalized on a custom payload designed to craft a forged message to the DVN with minimal alerts. Subsequently, the attackers launched a Distributed Denial-of-Service (DDoS) attack on the remaining RPCs, causing a failover to the compromised nodes and allowing their fraudulent commands to be accepted.

Responses and Implications

LayerZero attributes this sophisticated attack to a subgroup named TraderTraitor, part of the infamous Lazarus Group, notorious for multiple cryptocurrency heists in recent years. According to LayerZero, the incident could have been avoided if Kelp DAO had adopted a multi-DVN setup, which is a recommended industry standard.

In a statement, LayerZero noted that they had previously advised Kelp DAO on diversifying their DVN configuration. Kelp DAO, however, points fingers at LayerZero, arguing that their systems were not managing the targeted infrastructure and that the single-DVN setup was documented by LayerZero as appropriate.

In the aftermath, Kelp DAO has prioritized measures to prevent further contagion across the DeFi ecosystem. Partners like the Arbitrum Security Council promptly froze assets linked to the heist. Nevertheless, the ramifications are extensive, with decentralized liquidity protocol Aave experiencing a significant decrease in total value by nearly $8 billion.

Binance reported that the stolen funds were deposited into Aave v3 as collateral, leading to the borrowing of wrapped Ether and creating a $195 million debt on Aave. The rush of users withdrawing assets led to full utilization of Aave v3 lending pools, immobilizing over $5.1 billion in stablecoins.

As the crypto community grapples with the fallout, this incident underscores the critical need for robust security measures and cross-chain communication protocols to safeguard digital assets.

Security Week News Tags:blockchain security, crypto theft, Cryptocurrency, Cyberattack, DeFi, Ethereum, Kelp DAO, LayerZero, Lazarus Group, North Korea

Post navigation

Previous Post: SideWinder Targets Government Emails with Fake PDF Viewer
Next Post: Understanding Identity-Based Cyber Attacks and Defense

Related Posts

Venice Security Secures M for Access Management Venice Security Secures $33M for Access Management Security Week News
TransUnion Data Breach Impacts 4.4 Million TransUnion Data Breach Impacts 4.4 Million Security Week News
The Congressional Budget Office Was Hacked. It Says It Has Implemented New Security Measures The Congressional Budget Office Was Hacked. It Says It Has Implemented New Security Measures Security Week News
North Korean Hackers Target macOS with AppleScript Attacks North Korean Hackers Target macOS with AppleScript Attacks Security Week News
ThreatSpike Raises  Million in Series A Funding ThreatSpike Raises $14 Million in Series A Funding Security Week News
Gladinet CentreStack Flaw Exploited to Hack Organizations Gladinet CentreStack Flaw Exploited to Hack Organizations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic’s Claude Services Experience Major Disruption
  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic’s Claude Services Experience Major Disruption
  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark