North Korea's Lazarus Group Blamed for $290 Million Kelp DAO Heist in Most Sophisticated DeFi Attack on Record
North Korea's Lazarus Group has been blamed for a $290 million heist from Kelp DAO using RPC spoofing and a DDoS-triggered failover attack the most technically sophisticated DeFi infrastructure breach on record.

North Korea's Lazarus Group blamed for $290 million Kelp DAO cryptocurrency heist using RPC spoofing and DDoS failover attack on LayerZero cross-chain infrastructure
A North Korea-linked threat group has executed what security researchers are calling the most technically sophisticated attack ever recorded against decentralised finance infrastructure draining approximately $290 million in cryptocurrency from the Kelp DAO protocol through a precisely engineered combination of RPC spoofing and a coordinated distributed denial-of-service attack.
The incident has sent shockwaves through the global digital asset security community and carries direct implications for enterprise security architects across the GCC, where regulated crypto infrastructure is being built at speed under frameworks including the UAE's Virtual Assets Regulatory Authority (VARA) and SAMA's emerging digital asset guidelines in Saudi Arabia.
How the Attack Worked
The breach occurred at 17:35 UTC on Sunday, when attackers delivered a malicious instruction that drained 116,500 rsETH restaked ether from Kelp DAO's protocol, valued at approximately $292 million at the time of the attack.
Kelp DAO operates as a liquid restaking protocol, routing user-deposited ETH through EigenLayer to generate additional staking rewards. The protocol issues rsETH as a representation of those restaked positions. To validate cross-chain instructions, Kelp DAO relied on LayerZero a widely used cross-chain messaging infrastructure that connects blockchains and allows verified instructions to pass between them.
The attack targeted LayerZero's Decentralised Verifier Network (DVN), which uses multiple Remote Procedure Calls to check the integrity of cross-chain instructions before they are executed. The attackers compromised and poisoned two of those RPCs, injecting malicious payloads designed to forge verification messages with minimal detection alerts.
They then launched a sustained DDoS attack against the remaining legitimate RPCs, deliberately triggering a failover mechanism causing the network to route verification requests to the already-compromised nodes. With poisoned infrastructure now handling verification, the attackers' fraudulent drain instruction passed as valid.
The sophistication of the attack lies in this two-stage design: compromise the failover destination first, then force the failover to happen. It is a supply chain attack executed at infrastructure layer not at the application level where most DeFi security controls are concentrated.
Lazarus Group TraderTraitor Subgroup
LayerZero's post-incident analysis attributed the attack to TraderTraitor, a financially motivated subgroup operating within North Korea's Lazarus Group the same state-sponsored threat actor responsible for a string of high-value cryptocurrency heists over the past several years, including the $285 million Drift exploit and multiple exchange-level attacks.
The US Treasury's Office of Foreign Assets Control has previously sanctioned Lazarus Group entities, and the FBI has attributed billions in cumulative cryptocurrency theft to the group. The proceeds are widely assessed by Western intelligence agencies as a primary funding mechanism for North Korea's weapons programmes making these attacks a matter of national security concern for jurisdictions far beyond the immediate victims.
The Configuration Debate
The incident has exposed a significant dispute between Kelp DAO and LayerZero over responsibility. LayerZero states the attack could have been prevented had Kelp DAO implemented a multi-DVN setup a configuration using multiple independent verifier networks so that no single point of failure exists. LayerZero says it had previously communicated this best practice recommendation to Kelp DAO.
Kelp DAO disputes this characterisation, arguing that its single-DVN configuration was the documented default confirmed as appropriate by LayerZero during its Layer 2 expansion process.
Regardless of where responsibility ultimately lies, the architectural lesson is unambiguous: a 1-of-1 verifier configuration represents a critical single point of failure in any cross-chain infrastructure deployment. For enterprise security architects evaluating DeFi or cross-chain protocols whether for treasury management, tokenised asset settlement, or customer-facing digital asset services this incident sets a new baseline for due diligence requirements.
The Cascading Impact
The fallout extended well beyond Kelp DAO itself. Following the initial drain, attackers deposited stolen funds into Aave v3 as collateral and borrowed wrapped Ether creating approximately $195 million in leveraged debt positions. As users rushed to withdraw assets in response, Aave v3 lending pools reached full utilisation, blocking over $5.1 billion in stablecoins from withdrawal.
Decentralised liquidity protocol Aave registered a nearly $8 billion drop in total value locked in the immediate aftermath. Several partners including Arbitrum Security Council moved quickly to freeze assets connected to the attacker's wallet addresses, limiting further contagion but the systemic nature of the cascade illustrates how a single protocol breach can propagate across interconnected DeFi infrastructure at speed.
What GCC Enterprise Security Leaders Must Take From This
For security leaders at GCC financial institutions, digital asset platforms, and enterprises operating in or evaluating regulated crypto markets, three operational conclusions emerge from this incident.
Cross-chain infrastructure is an enterprise attack surface. The LayerZero DVN is not an obscure component it is widely used across the DeFi ecosystem. Any enterprise with exposure to protocols built on cross-chain messaging infrastructure inherits a portion of that attack surface. Security assessments must extend to infrastructure dependencies, not just application-layer controls.
Verifier diversity is now a baseline security requirement. The 1-of-1 DVN configuration that enabled this attack is architecturally equivalent to relying on a single firewall with no redundancy. Multi-DVN configurations should be treated as a minimum standard for any enterprise-grade deployment involving cross-chain assets.
Nation-state actors are operating at DeFi infrastructure layer. Lazarus Group / TraderTraitor has now demonstrated the capability and intent to target cross-chain messaging infrastructure directly not just exploit smart contract vulnerabilities or phish private keys. This raises the threat level for all participants in regulated digital asset markets, including those operating under VARA in the UAE and emerging SAMA digital asset frameworks in Saudi Arabia.
For broader context on how AI-driven threat actors are compressing the timeline between vulnerability discovery and exploitation, see our analysis of what GCC CISOs must do now. For ongoing coverage of financial sector cybersecurity across the region, follow our Threat Intelligence and Policy & Compliance coverage.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.