Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
cryptocurrency-platform-riskstate-sponsored-espionagedata-exfiltration-method

Cross-chain bridge failures at CrossCurve and KelpDAO expose verifier trust risks

Updated 1mo agoFirst seen May 25, 20265 sources

CrossCurve disclosed a roughly $3 million cross-chain bridge exploit after attackers abused a validation weakness, prompting the protocol to pursue legal action while investigators worked to trace the stolen funds. Reporting on the incident said the attack targeted the bridge’s transaction verification logic rather than a simple wallet compromise, underscoring how weaknesses in cross-chain message validation can let adversaries authorize fraudulent transfers and drain locked assets.

A larger breach hit KelpDAO, where attackers stole about $290 million in rsETH by exploiting its LayerZero-based bridge path with effectively 1-of-1 DVN verification, allowing a forged packet to be accepted on Ethereum without a legitimate source-chain transaction. The theft was widely attributed to North Korea-linked Lazarus/TraderTraitor, and recovery efforts later included burning more than 117,000 rsETH held by the exploiter on Arbitrum, restoring backing through an Aave-controlled recovery wallet, increasing bridge requirements to four independent attestors and 64 block confirmations, and beginning a migration to Chainlink CCIP after investigators characterized the incident as an operational and verification failure rather than a confirmed public smart-contract bug.

Share:
Cross-chain bridge failures at CrossCurve and KelpDAO expose verifier trust risks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
May 13, 20262mo ago

KelpDAO announces withdrawals reopening and bridge hardening

KelpDAO said rsETH remained fully backed and that withdrawals were expected to resume within 24 hours after the first tranche was returned to the smart contract. It also announced security changes including four independent attestors, 64 block confirmations, deprecation of some layer-2 routes, and migration to Chainlink CCIP.

KelpDAO and Aave burn exploiter-held rsETH on Arbitrum

KelpDAO and Aave completed a recovery step by burning 117,132 rsETH held by the exploiter on Arbitrum. Kelp said the approximately $278 million backing would be restored in tranches from the Aave Recovery Guardian multisig.

May 4, 20262mo ago

Public PoC details KelpDAO's 1-of-1 DVN verification failure

A GitHub proof-of-concept published technical evidence that KelpDAO's LayerZero route effectively relied on single-DVN 1-of-1 verification, allowing a forged packet to be accepted without a legitimate source-chain transaction. The write-up concluded the immediate cause was single-verifier failure and the broader cause was insecure bridge configuration.

Apr 21, 20262mo ago

North Korean TraderTraitor/Lazarus linked to KelpDAO heist

Reporting in April linked the KelpDAO theft to TraderTraitor, a Lazarus Group unit tied to North Korea. LayerZero said the attackers compromised external verification infrastructure, poisoned RPC data, disrupted backups, and used DDoS pressure to force reliance on falsified transaction data.

Apr 18, 20262mo ago

KelpDAO blocks a second forged withdrawal attempt

A second forged packet for 40,000 rsETH became claimable, but KelpDAO blacklisted the recipient before the attacker could complete the withdrawal. Cyvers said this prevented roughly another $100 million in losses.

KelpDAO bridge attack drains about 116,500 rsETH

Attackers fraudulently withdrew 116,500 rsETH from KelpDAO's Ethereum-side OFT adapter, an incident later valued at roughly $290 million to $294 million. The exploit abused KelpDAO's cross-chain bridge verification path on the Unichain-to-Ethereum route.

Feb 2, 20265mo ago

CrossCurve says it will pursue legal action after exploit

After the $3 million exploit, CrossCurve publicly threatened legal action in response to the attack. This marked the project's initial public response to the incident.

CrossCurve bridge exploited for about $3 million

CrossCurve suffered a cross-chain bridge exploit that resulted in losses of roughly $3 million. Reporting on Feb. 2 describes the incident as exposing a validation flaw in the bridge.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cross-chain bridge failures at CrossCurve and KelpDAO expose verifier trust risks | Mallory