LayerZero Releases Report on rsETH Attack, Rebuilds Affected Infrastructure

iconKuCoinFlash
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
LayerZero has released an on-chain incident report detailing the rsETH attack. On April 18, KelpDAO’s rsETH bridge was compromised, resulting in the loss of approximately 116,500 rsETH ($292 million). Security firms traced the attack to North Korean hackers. The exploit targeted KelpDAO’s single-validator configuration, not the LayerZero protocol itself. Attackers gained access using a stolen session key and manipulated internal RPC nodes. LayerZero has since deployed a protocol update, rebuilt its infrastructure using a zero-trust architecture, and is collaborating with law enforcement to trace the stolen funds.

BlockBeats report: On May 20, LayerZero released a report on the rsETH attack. On April 18, the KelpDAO rsETH bridge, built on the LayerZero cross-chain messaging protocol, was compromised, resulting in the theft of approximately 116,500 rsETH (valued at around $292 million). Multiple security firms attribute this attack to the North Korean hacking group TraderTraitor (UNC4899). The attack did not affect the LayerZero protocol itself or other OApps, but targeted only KelpDAO’s single-validator configuration bridge.


The attack began on March 6, when the attacker used social engineering to obtain the session key of a LayerZero Labs developer, infiltrated their RPC cloud environment, and compromised internal RPC nodes. These nodes were implanted with memory patches that returned normal responses to monitoring tools while providing tampered blockchain state information to LayerZero Labs’ DVN (Decentralized Verifier Network). The attacker then launched a DoS attack against external RPC providers, forcing the DVN to rely exclusively on the compromised internal nodes, ultimately enabling the generation of valid proofs for forged cross-chain messages. Due to KelpDAO’s single-verifier configuration, the target contract accepted the single proof and unlocked rsETH.


Following the incident, LayerZero Labs implemented several measures:

Change operational stance to require that channels in which its DVN participates meet minimum security configurations (rejecting use as the sole validator signature);

Completely rebuild the affected infrastructure using a zero-trust architecture and just-in-time privilege escalation mechanisms;

Collaborate with ecosystem partners to continuously enhance security configurations. Simultaneously, work with law enforcement agencies and security firms to investigate, attribute, and track funds.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.