The KelpDAO bridge lost $292M. The smart contracts were fine.
Bridge security has always been a bet on whoever runs the verification infrastructure. Audited contracts mean nothing if the verifier is compromised.

CryptoVibe Desk · layerzero · bridge-security · kelpdao

- →On April 18, KelpDAO's rsETH bridge released 116,500 rsETH against a fraudulent burn, extracting roughly $292 million through compromised off-chain DVN infrastructure.
- →The exploit bypassed audited smart contracts entirely, proving that single-verifier bridges carry an infrastructure risk category no standard audit can surface.
- →Watch whether Aave, Compound, or another major lending protocol mandates multi-DVN configuration for whitelisted bridge collateral in a governance vote before end of Q2 2026.
- DVN (Decentralized Verifier Network) → A node or set of nodes that confirms a cross-chain message is legitimate before the destination blockchain executes it.
- rsETH → KelpDAO's liquid restaking token, representing staked ETH plus restaking yield, usable across DeFi protocols without unstaking.
- Single-DVN configuration → A bridge setup that trusts exactly one verifier to approve cross-chain messages, instead of requiring agreement from multiple independent verifiers.
- TVL (Total Value Locked) → The total dollar value of assets deposited into a DeFi protocol, used as a proxy for its size and activity.
LayerZero's cross-chain messaging model routes messages through one or more Decentralized Verifier Networks. A DVN picks up a source-chain event, confirms it, and only then does the destination chain execute. The bridge's security reduces to the security of that verification step. On April 18, that single step failed.
KelpDAO's rsETH bridge released 116,500 rsETH on the destination chain against a burn that, per Chainalysis's analysis, never actually occurred. The attacker compromised the off-chain DVN infrastructure. The smart contracts were fine. This is a trust-assumption problem, not a code-review problem: single-DVN bridges carry a risk category that no audit can surface.
Call it the certificate-authority failure mode. A compromised CA issues valid-looking certificates, and nothing downstream raises an alarm because the signatures check out. Single-DVN bridges run that same architecture without anything analogous to Certificate Transparency logs. Chainalysis flagged exactly this: standard on-chain monitoring missed the attack because the transactions appeared valid on-chain. There was nothing anomalous to detect at the contract layer.
The immediate damage is approximately $292 million, extracted via the April 18 bridge manipulation. The downstream number requires more care: DeFi TVL dropped roughly $13 billion in the aftermath, but that figure reflects leveraged-position unwinds as much as direct capital loss. Aave saw approximately $8.45 billion leave over 48 hours this past weekend. Spark moved in the opposite direction, growing from $1.8 billion to $2.9 billion TVL over the same period, which looks more like rotation than sector exit.
LayerZero's incident statement says preliminary indicators point to DPRK's Lazarus Group, specifically the TraderTraitor cluster, as the responsible party. Chainalysis's analysis echoes that attribution. Both should be read as allegations from organizations closest to the incident, not settled findings. What isn't disputed: LayerZero frames the incident as isolated to KelpDAO's rsETH single-DVN configuration and says multi-DVN deployments elsewhere on the network weren't exposed.
That framing is where the repricing story starts. If single-DVN is the exploitable surface, then any protocol routing significant TVL through a single-verifier bridge carries risk that doesn't show up in a standard smart-contract audit. The tradeoff is latency and cost for security. Multi-DVN requires more validators to agree before execution, which adds confirmation time and gas overhead. Single-DVN was a performance optimization that also happened to be the attack surface.
The follow-up will appear in governance queues and deployment dashboards before it shows anywhere else. Protocols using LayerZero for cross-chain operations should be auditing their DVN configuration now. Multi-DVN raises the cost of compromise without eliminating it. But running single-DVN at meaningful TVL concentrations isn't a configuration choice anymore. After April 18, it's a documented risk premium.
LayerZero should hard-deprecate single-DVN configurations for bridges above $50M TVL and mandate multi-DVN as the minimum deployment standard before any new protocol integration goes live.
Whether Aave, Compound, or another major lending protocol adds multi-DVN configuration as a hard requirement for whitelisted bridge collateral in a published governance vote before end of Q2 2026.
Primary links and supporting reads used by the desk for this story.
Forward this.











