Crypto Community Slams LayerZero: More Verifiers Won’t Stop The Next $290M Hack

Crypto Community Slams LayerZero: More Verifiers Won’t Stop The Next 0M Hack

LayerZero is dealing with heavy criticism for its response to the latest $290 million KelpDAO exploit after the omnichain interoperability protocol blamed Kelp’s 1-of-1 verifier configuration for the incident.

Associated Studying

LayerZero Blames KelpDAO For $290M Exploit

Over the weekend, liquid restaking protocol KelpDAO was the sufferer of an assault that drained over $290 million in rsETH from the undertaking after malicious actors exploited a weak spot within the protocol’s LayerZero-powered bridge.

Two days later, LayerZero addressed the incident, which grew to become the biggest DeFi hack of 2026, simply weeks after Drift Protocol’s $285 million exploit shocked the business.

LayerZero attributed the “highly sophisticated attack” to North Korea’s Lazarus Group, claiming that it was a crypto infrastructure assault quite than a protocol exploit, and affirming that “there is zero contagion to any other cross-chain assets or applications.”

LayerZero’s autopsy. Supply: X

They defined that the protocol is constructed on a “foundation of modular, application-configurable security,” utilizing Decentralized Verifier Networks (DVNs), unbiased entities accountable for verifying the integrity of cross-chain messages.

The malicious actors allegedly poisoned downstream RPC infrastructure by “compromising a quorum of the RPCs the LayerZero Labs DVN relied upon to verify transactions.”

Per the submit, the attackers swapped binaries for a customized payload to forge messages and used DDoS assaults to pressure failover to the poisoned nodes, triggering the DVN into confirming faux transactions.

Based mostly on this, LayerZero positioned duty on KelpDAO for utilizing a 1-of-1 verifier configuration as a substitute of the multi-DVN suggestions: “This incident was isolated entirely to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup.”

Crypto Community Criticizes ‘Lack Of Accountability’

The crypto group reacted to the autopsy, sharing its issues about LayerZero’s response and criticizing the protocol for putting all duty solely on Kelp’s safety setup.

“Imagine building a bridge and vehicles pays to cross, the bridge collapsed and you said it’s their fault for crossing the bridge. A classic clownery act from Bunch of clowns with zero accountability,” X consumer Saint wrote.

Others questioned why LayerZero included a “1-of-1” configuration if the aim of a DVN is customizable/modular safety. “If the system allows this option, it’s not the fault of the customer who chose it—it’s a fundamental design flaw by the system that permitted it,” consumer Ditto wrote.

“At the end of the day, the fact remains that the DVN RPC was compromised. DVN is a LayerZero product, and they are the ones who sold it to these teams,” he continued.

Equally, Chainlink group supervisor Zach Rynes accused the protocol of deflecting duty for the compromise of their very own DVN node.

He additionally criticized them for “throwing KelpDAO under the bus” for trusting LayerZero Labs’ setup that they “willingly support and only blocked after getting hacked, all while claiming everything worked as designed.”

In the meantime, Yearn Finance core workforce developer Artem Okay famous on X that the assault was described as a compromise of an RPC node and RPC poisoning, however that their very own infrastructure is what was compromised. “Given it doesn’t say how the breach has occurred, I wouldn’t rush re-enabling the bridges,” he added.

Unsuitable Prognosis, Unsuitable Repair?

Analyst The Good Ape additionally claims that LayerZero made the unsuitable analysis and provided the unsuitable resolution. Notably, the protocol’s autopsy prompt migrating all functions with 1-of-1 DVN configurations to multi-DVN setups to stop comparable assaults.

Nonetheless, the analyst identified that multi-verifiers gained’t cease the following multi-million-dollar assault, asserting that they may fail as all DVNs learn chain states from the identical handful of RPC suppliers, that are largely clustered on AWS or GCP.

If 5 “independent” DVNs learn from the identical three RPC suppliers, an attacker who poisons these three RPCs will poison all 5 verifiers concurrently. “If all your verifiers get fooled in the same way at the same time, the math collapses back to 1-of-1. Five clones are not five witnesses,” he added.

Associated Studying

To unravel this, the analyst prompt that each verifier runs its personal full node on totally different shopper software program, hosted on totally different cloud suppliers, maintained by totally different ops groups, peered with totally different subsets of the Ethereum community.

“The fix isn’t multi-anything. The fix is that verifiers should attest to their own substrate, not just to chain state. until you can audit a DVN’s upstream topology, which RPC providers, which client software, which clouds, which regions, ‘M-of-N secured’ is marketing copy for a property that hasn’t actually been built. Lazarus didn’t break cryptography on April 18. They broke three servers,” he concluded.

LayerZero, TOTAL
The whole crypto market capitalization is at $2.54 trillion within the one-week chart. Supply: TOTAL on TradingView

Featured Picture from Unsplash.com, Chart from TradingView.com

Supply hyperlink

bitcoin
Bitcoin (BTC) $ 59,851.00 2.71%
ethereum
Ethereum (ETH) $ 1,549.24 5.64%
tether
Tether (USDT) $ 0.998543 0.02%
bnb
BNB (BNB) $ 559.53 1.55%
usd-coin
USDC (USDC) $ 0.999674 0.00%
xrp
XRP (XRP) $ 1.03 5.06%
solana
Solana (SOL) $ 68.04 1.08%
tron
TRON (TRX) $ 0.321377 2.05%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 0.60%
staked-ether
Lido Staked Ether (STETH) $ 2,265.05 3.46%
hyperliquid
Hyperliquid (HYPE) $ 62.66 1.70%
dogecoin
Dogecoin (DOGE) $ 0.074151 3.73%
usds
USDS (USDS) $ 0.999504 0.01%
rain
Rain (RAIN) $ 0.015679 1.44%
leo-token
LEO Token (LEO) $ 9.21 1.41%
zcash
Zcash (ZEC) $ 408.90 1.93%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67 3.22%
stellar
Stellar (XLM) $ 0.174244 7.60%
lab
LAB (LAB) $ 18.77 14.70%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00 3.12%
monero
Monero (XMR) $ 312.55 0.66%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762 0.02%
canton-network
Canton (CC) $ 0.147905 2.75%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93 3.47%
whitebit
WhiteBIT Coin (WBT) $ 48.33 3.39%
chainlink
Chainlink (LINK) $ 7.18 4.22%
cardano
Cardano (ADA) $ 0.14169 5.53%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31 3.39%
usd1-wlfi
USD1 (USD1) $ 0.999052 0.03%
susds
sUSDS (SUSDS) $ 1.08 0.16%
dai
Dai (DAI) $ 0.999615 0.00%
ethena-usde
Ethena USDe (USDE) $ 0.998332 0.01%
the-open-network
Gram (prev. Toncoin) (GRAM) $ 1.56 2.48%
bitcoin-cash
Bitcoin Cash (BCH) $ 191.72 1.26%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00 3.12%
litecoin
Litecoin (LTC) $ 41.24 1.27%
hedera-hashgraph
Hedera (HBAR) $ 0.07255 3.27%
hashnote-usyc
Circle USYC (USYC) $ 1.13 0.01%
weth
WETH (WETH) $ 2,268.37 3.40%
global-dollar
Global Dollar (USDG) $ 0.999504 0.02%
paypal-usd
PayPal USD (PYUSD) $ 0.999617 0.01%
sui
Sui (SUI) $ 0.678103 1.60%
usdt0
USDT0 (USDT0) $ 0.998824 0.03%
avalanche-2
Avalanche (AVAX) $ 6.09 6.88%
crypto-com-chain
Cronos (CRO) $ 0.054601 3.41%
shiba-inu
Shiba Inu (SHIB) $ 0.000004 5.35%
tether-gold
Tether Gold (XAUT) $ 4,000.91 0.25%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
near
NEAR Protocol (NEAR) $ 1.80 7.88%
ondo-us-dollar-yield
Ondo US Dollar Yield (USDY) $ 1.13 0.31%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.22 0.04%
bittensor
Bittensor (TAO) $ 210.55 4.45%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.057228 2.35%
pax-gold
PAX Gold (PAXG) $ 4,004.28 0.32%
uniswap
Uniswap (UNI) $ 2.84 3.90%
aster-2
Aster (ASTER) $ 0.619899 0.64%
worldcoin-wld
Worldcoin (WLD) $ 0.472324 9.48%
ripple-usd
Ripple USD (RLUSD) $ 0.999929 0.01%
okb
OKB (OKB) $ 75.00 1.41%
htx-dao
HTX DAO (HTX) $ 0.000002 2.01%
ondo-finance
Ondo (ONDO) $ 0.307412 3.32%
little-pepe-5
Little Pepe (LILPEPE) $ 2.16 99,999.99%
falcon-finance
Falcon USD (USDF) $ 0.993189 0.07%
syrupusdc
syrupUSDC (SYRUPUSDC) $ 1.15 0.04%
mantle
Mantle (MNT) $ 0.429091 15.41%
polkadot
Polkadot (DOT) $ 0.827529 7.31%
pi-network
Pi Network (PI) $ 0.128421 1.46%
usdd
USDD (USDD) $ 0.998451 0.06%
bfusd
BFUSD (BFUSD) $ 0.998295 0.04%
aave
Aave (AAVE) $ 82.91 1.70%
sky
Sky (SKY) $ 0.051424 5.57%
internet-computer
Internet Computer (ICP) $ 2.14 3.64%
bitget-token
Bitget Token (BGB) $ 1.63 2.96%
ethereum-classic
Ethereum Classic (ETC) $ 6.93 3.05%
dexe
DeXe (DEXE) $ 22.91 1.01%
morpho
Morpho (MORPHO) $ 1.63 7.40%
memecore
MemeCore (M) $ 0.826037 13.02%
united-stables
United Stables (U) $ 0.9996 0.02%
pepe
Pepe (PEPE) $ 0.000002 8.49%
jupiter-perpetuals-liquidity-provider-token
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00 2.64%
blockchain-capital
Blockchain Capital (BCAP) $ 107.03 0.00%
quant-network
Quant (QNT) $ 64.04 6.72%
eutbl
Spiko EU T-Bills Money Market Fund (EUTBL) $ 1.20 0.09%
usdtb
USDtb (USDTB) $ 0.999325 0.05%
kucoin-shares
KuCoin (KCS) $ 6.70 4.61%
jito-staked-sol
Jito Staked SOL (JITOSOL) $ 124.46 4.71%
stable-2
​​Stable (STABLE) $ 0.036781 1.59%
janus-henderson-anemoy-treasury-fund
Janus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11 0.01%
kelp-dao-restaked-eth
Kelp DAO Restaked ETH (RSETH) $ 2,404.69 3.37%
cosmos
Cosmos Hub (ATOM) $ 1.61 2.79%
superstate-short-duration-us-government-securities-fund-ustb
Invesco Short Duration US Government Securities Fund (USTB) $ 11.13 0.01%
binance-peg-weth
Binance-Peg WETH (WETH) $ 2,262.26 3.62%
render-token
Render (RENDER) $ 1.50 4.93%
rocket-pool-eth
Rocket Pool ETH (RETH) $ 2,631.35 3.29%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.07182 2.36%
usdgo
USDGO (USDGO) $ 1.00 0.00%
binance-bridged-usdc-bnb-smart-chain
Binance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945 0.02%
kaspa
Kaspa (KAS) $ 0.027543 2.08%
algorand
Algorand (ALGO) $ 0.08319 7.80%
wbnb
Wrapped BNB (WBNB) $ 759.61 1.56%
Scroll to Top