ChainBleedv0.1 · open intel
← back to feed·MULTIBRIDGE2026-04-18 · 1mo ago
Incident · DEFILLAMA

Kelp

LayerZero OFT bridge exploit
Estimated loss
$293.00M
VERDICT —CONFIG LAYER
OFT/OApp source code was not the failure; the DVN/Executor configuration (1-of-1 verifier) and off-chain RPC infrastructure were. A pre-deployment review should have flagged the verifier-count config as a Critical, but the bug class is config + infra, not logic.
▰ METHOD
LayerZero OFT bridge exploit
BRIDGEBYTECODE CATCHABLEAI SCANNABLE
Root cause

KelpDAO's rsETH OFT (LayerZero v2) was configured with a 1-of-1 DVN setup using only the LayerZero Labs DVN as the verifier between source and destination endpoints. The OFT contract itself was structurally sound; the exploit hit the off-chain verification layer. Attackers (attributed by multiple firms to Lazarus Group) compromised two RPC nodes that the LayerZero Labs DVN relied on to read source-chain state, then induced the DVN to attest to inbound packet hashes corresponding to mints that never occurred on the origin chain. Because the OApp accepted any payload signed by the single configured DVN, the destination `_lzReceive` minted 116,500 rsETH against fabricated source events. The root cause is configuration plus infrastructure compromise, not contract logic — LayerZero later acknowledged the 1-of-1 default was a mistake; ~47% of active LayerZero OApps used the same posture.

Forensic narrative

Classification: Infrastructure. Technique: LayerZero OFT bridge exploit. Target type: DeFi Protocol. Affected chains: Ethereum, Arbitrum. Implementation language: Solidity.

Primary source
https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/
Sourced from
DefiLlama Hacks dataset · api.llama.fi/hacks
Technical record
chain
multichain
protocol
Kelp
bug_class
bridge
date_occurred
2026-04-18
loss_usd
$293,000,000
classification
Infrastructure
technique
LayerZero OFT bridge exploit
target_type
DeFi Protocol
language
Solidity
source_id
dl:3946
Related — same bug class· bridge
2026-05-16
25d ago
ETH
Adshares
Bridge-Minter Fake-Mint Exploit (wADS)
bridge
$628.0K
AMBIGUOUS
2026-05-15
26d ago
MULTI
THORChain
Cross-Chain Router Exploit (multi-chain drain)
bridge
$10.70M
AMBIGUOUS
2026-04-29
1mo ago
BASE
Syndicate
Commons Bridge Exploit
bridge
$380.0K
UNRATED
2026-04-29
1mo ago
MULTI
Syndicate
Exploit
bridge
$330.0K
UNRATED
2026-04-27
1mo ago
MULTI
ZetaChain
GatewayEVM Contracts Exploit
bridge
$300.0K
UNRATED
2026-04-12
1mo ago
MULTI
Hyperbridge
Fake State Proof
bridge
$2.50M
UNRATED
ChainBleed — live web3 threat intelligence