Skip to main content
Mallory
Back to intelligence
cryptocurrency-platform-riskstate-sponsored-espionagedefense-evasion-methodcloud-service-vulnerability

North Korean Hackers Blamed for $290 Million Kelp DAO Crypto Theft

Updated 6h agoFirst seen Apr 20, 202637 sources

More than $290 million in cryptocurrency was stolen from Kelp DAO after attackers compromised infrastructure used to verify cross-chain messages and exploited the platform’s rsETH configuration. According to LayerZero, the intruders abused Kelp’s single-verifier setup rather than a redundant multi-verifier model, allowing them to mint unbacked rsETH and use it as collateral to borrow real Ether and stablecoins from other platforms, including Aave. LayerZero said preliminary indicators point to North Korea’s TraderTraitor group, which is linked to the broader Lazarus operation.

Kelp DAO disputed LayerZero’s account and argued that LayerZero’s own servers were compromised, setting up a public dispute over responsibility for one of the largest crypto thefts reported this year. LayerZero’s post-mortem said the attackers also used DDoS activity against backup systems and self-destructing tools to hinder detection and complete the theft. Law enforcement has been notified, Aave is evaluating remediation, and the incident adds to a long-running pattern of DPRK-linked cryptocurrency thefts that investigators say have generated billions of dollars over the past several years.

Share:
North Korean Hackers Blamed for $290 Million Kelp DAO Crypto Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

21 events from the most recent confirmed update back to the earliest known activity.

21 EVENTS
Jun 5, 20261d ago

Protocols announce migrations to Chainlink CCIP after Kelp exploit

By 2026-06-05, Virtuals Protocol, Pleasing Market, and Zest Protocol had announced migrations or integrations with Chainlink CCIP, with Virtuals shifting more than $700 million in VIRTUAL cross-chain infrastructure after a security review tied to the Kelp DAO incident. The article says the migration wave accelerated after the April Kelp DAO exploit and helped drive more than $1.1 billion in announced token value to CCIP in one week.

Chainlink CCIP Draws $1.1 Billion in Value in One Week as Virtuals Join Migration Wave - "The Defiant"
Jun 1, 20265d ago

Analysts say attacker laundered nearly all unfrozen Kelp exploit funds

On-chain analysts reported that the DPRK-linked attacker behind the Kelp DAO exploit had laundered nearly all of the roughly $220 million in unfrozen funds through THORChain, Wasabi, Tornado Cash, and Umbra, leaving only about $1.7 million in the original exploiter wallet. The update indicated that the main materially recoverable assets were now limited to the approximately $71 million previously frozen on Arbitrum.

Kelp DAO Hacker Has Laundered Nearly All $220M in Unfrozen Funds, Closing the Recovery Window - "The Defiant"
May 20, 202617d ago

LayerZero publishes forensic report on Kelp exploit attack chain

LayerZero Labs published a forensic report saying the KelpDAO exploit began on 2026-03-06 after a developer was socially engineered into cloning a malicious GitHub repository, leading to compromise of LayerZero RPC infrastructure and forged DVN signing. The report said Mandiant and CrowdStrike attributed the operation with high confidence to UNC4899/TraderTraitor and detailed how Kelp's bridge had been downgraded from a 2-of-2 to a 1-of-1 verifier setup before the theft.

LayerZero's Incident Report Says Kelp Downgraded From 2-of-2 to 1-of-1 DVN Before $292M Exploit - "The Defiant"
May 13, 202624d ago

Kelp DAO burns attacker rsETH and sets withdrawal reopening plan

Kelp DAO said it burned rsETH held by the exploiter on Arbitrum and published a recovery plan aimed at restoring liquidity and resuming normal withdrawals in about two weeks. As part of the process, it said Aave's Recovery Guardian multisig would be used to refill rsETH reserves during the recovery period.

Kelp DAO Burns Exploiter's rsETH on Arbitrum, Plans Two-Week Withdrawal Reopening: Kelp DAO - "The Defiant"
May 11, 202626d ago

Judge modifies restraint to allow vote on moving frozen Arbitrum ETH

A U.S. District Court judge in the Southern District of New York modified the earlier restraining notice that had blocked movement of 30,766 ETH frozen on Arbitrum after the Kelp DAO exploit. The ruling cleared the way for a vote on transferring the roughly $71 million in recovered cryptocurrency to affected services while leaving competing ownership claims unresolved.

US court clears way for vote on moving $71M in crypto stolen by North Korea | NK News
May 4, 20261mo ago

Aave seeks to vacate court restraint on frozen Arbitrum ETH

Aave LLC filed an emergency motion in the U.S. District Court for the Southern District of New York to vacate the restraining notice targeting about 30,765 ETH frozen on Arbitrum after the Kelp DAO exploit. Aave argued the assets remain property of the theft victims, challenged the evidence tying the funds to North Korea, and said the restraint was obstructing the DeFi-led recovery plan.

Aave Asks Court to Vacate Restraining Notice Targeting Recovered Kelp DAO Assets - "The Defiant"
May 1, 20261mo ago

Attorney seeks court-backed seizure of frozen Arbitrum ETH

On 2026-05-01, attorney Charles Gerstein served Arbitrum DAO with a restraining notice and three writs of execution authorized by the U.S. District Court for the Southern District of New York, seeking to seize more than 30,700 ETH frozen after the Kelp DAO exploit. The effort argues the assets are effectively North Korean state property tied to Lazarus-linked activity and attempts to redirect them to holders of unpaid U.S. judgments against North Korea.

Lawyer Attempts to Seize Frozen ETH Linked to Kelp Exploit From Arbitrum DAO - "The Defiant"
Apr 28, 20261mo ago

DeFi United publishes technical rsETH recovery plan

DeFi United outlined a technical plan to restore rsETH backing after the Kelp DAO exploit, including governance proposals, temporary oracle changes, and controlled liquidations targeting about 107,000 rsETH in attacker-linked Aave and Compound positions. The coalition said it had secured recapitalization commitments in tranches, while LayerZero Labs pledged more than 10,000 ETH through direct support and Aave liquidity assistance.

DeFi United Outlines Technical Path To Make Kelp's rsETH Whole - "The Defiant"
Apr 24, 20261mo ago

DeFi United reports recovery pledges and Mantle loan proposal

By April 24, the Kelp- and Aave Labs-led 'DeFi United' recovery effort said 73,700 ETH of the exploit-related shortfall had been filled and public commitments totaled 43,500 ETH, leaving about 89,500 ETH outstanding. The update also said Mantle proposed a loan of up to 30,000 ETH to Aave DAO to help address the remaining bad debt, with public support from Bybit CEO Ben Zhou and other DeFi participants.

DeFi United Fundraising Chips Away at Kelp Exploit Shortfall - "The Defiant"
Apr 23, 20261mo ago

Aave and partners launch DeFi United recovery initiative

On 2026-04-23, Aave and major DeFi firms including Lido and EtherFi launched a coordinated recovery effort called 'DeFi United' to recapitalize rsETH, prevent forced liquidations, and reduce bad debt after the KelpDAO exploit destabilized lending markets. The initiative focused on restoring collateral backing and containing ecosystem fallout rather than relying solely on asset recovery.

KelpDAO hack news: Aave leads DeFi bailout push after $292M crypto exploit
Apr 21, 20262mo ago

Aave partially reopens WETH supply after emergency freeze

On April 21, Aave partially rolled back emergency controls imposed after the Kelp DAO exploit by reopening WETH supply on its Ethereum Core V3 market. WETH collateralization remained disabled and other affected markets stayed frozen while the protocol continued managing contagion risk and potential bad debt.

Aave Partially Unfreezes WETH After Kelp Bridge Exploit - "The Defiant"

Arbitrum freezes 30,766 ETH tied to KelpDAO exploit

Arbitrum said its Security Council used emergency powers to freeze about 30,766 ETH, worth more than $71 million, linked to the KelpDAO exploit after receiving identity information about the exploiter from law enforcement. The action marked a concrete containment step beyond the earlier general law-enforcement response.

Arbitrum Freezes 30,766 ETH Linked to KelpDAO Exploit - "The Defiant"
Apr 20, 20262mo ago

LayerZero ends support for single-verifier message signing

In response to the Kelp DAO exploit, LayerZero said it will stop signing messages for applications using a single-verifier setup. The move forces affected applications to migrate away from the 1-of-1 DVN model criticized after the theft.

Kelp DAO hits back at LayerZero for trying to shift the blame after a massive exploit

Fluid and partners launch aWETH Redemption Protocol

Following the Kelp DAO exploit's impact on Aave's fully utilized WETH market, Fluid and partners including Lido, Ether.fi, 1inch, 0x, and Kyber launched an emergency aWETH Redemption Protocol to let users swap stuck aWETH exposure into wstETH or weETH collateral. The mechanism was built in under 24 hours and processed 58,510 aWETH, about $136 million, within its first 48 hours, though it did not reduce Aave's modeled bad debt.

DeFi Protocols Launch Joint Escape Hatch for Aave ETH Lenders and Loopers - "The Defiant"

Aave estimates $123.7M-$230.1M bad debt from Kelp exploit

Aave service providers published an incident report stating that 89,567 stolen rsETH were deposited across seven attacker-controlled wallets and estimating potential bad debt of $123.7 million to $230.1 million depending on loss allocation and oracle updates. The report also recommended immediately pausing Aave's Umbrella WETH safety module while mitigation efforts were coordinated.

Aave Models $124M to $230M in Bad Debt From Kelp Exploit - "The Defiant"

Law enforcement and Aave begin response to Kelp theft

Following disclosure of the incident, law enforcement became involved and Aave began assessing remediation related to the stolen funds and downstream impact. These actions marked the initial external response to the theft.

Kelp DAO disputes LayerZero's account of the breach

After LayerZero's attribution, a Kelp source rejected the claim that its configuration choices were to blame and instead said LayerZero's own servers were compromised. The dispute highlighted conflicting explanations for how the theft occurred.

LayerZero publicly attributes Kelp theft to North Korea

By Monday, LayerZero said preliminary indicators linked the theft to North Korea's TraderTraitor group, associated with the Lazarus operation. Its post-mortem said the incident was isolated to Kelp and argued Kelp had not adopted LayerZero's recommended multi-DVN redundancy.

Apr 18, 20262mo ago

SparkLend, Fluid, Lido, and Ethena take precautionary actions after Kelp exploit

In the immediate aftermath of the April 18 Kelp DAO exploit, SparkLend and Fluid froze affected markets while Lido and Ethena paused related functions as a precaution against contagion from stranded rsETH across more than 20 chains. These measures expanded the response beyond Kelp DAO and Aave to other major DeFi protocols exposed to the incident.

Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains

Kelp DAO pauses rsETH contracts and blocks further theft attempts

After detecting suspicious cross-chain rsETH activity, Kelp DAO paused rsETH contracts on Ethereum mainnet and several Layer 2 networks while investigating the April 18 exploit. The freeze reportedly blocked two additional attempted thefts totaling roughly $100 million.

Nearly $300M stolen from Kelp DAO cross-chain bridge heist | brief | SC Media

Hackers steal more than $290 million from Kelp DAO

Over the weekend, attackers stole more than $290 million in cryptocurrency from Kelp DAO by compromising infrastructure used to verify cross-chain messages and exploiting Kelp's single-verifier configuration for rsETH. The attackers minted unbacked rsETH and used it as collateral to borrow real Ether and stablecoins from platforms including Aave.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

North Korean Hackers Blamed for $290 Million Kelp DAO Crypto Theft | Mallory