KelpDAO rsETH / LayerZero 브릿지 보안 사고 리포트

2026-04-28 Sooho

https://www.sooho.io/articles/kelpdao-rseth-layerzero-%EB%B8%8C%EB%A6%BF%EC%A7%80-%EB%B3%B4%EC%95%88-%EC%82%AC%EA%B3%A0-%EB%A6%AC%ED%8F%AC%ED%8A%B8

Attachments

1777012774817.pdf (3 MB)

Thumbnail for KelpDAO rsETH / LayerZero 브릿지 보안 사고 리포트

SOOHO.IO's bulletin describes the April 18, 2026 KelpDAO rsETH bridge incident, in which 116,500 rsETH, about $290 million to $294 million, was released from the Ethereum escrow contract without a valid source-chain burn. The source frames the failure as an off-chain trust and configuration problem rather than a smart contract bug: KelpDAO relied on a single LayerZero DVN, and the verifier's RPC infrastructure accepted a forged cross-chain message. The attacker moved stolen rsETH into lending protocols before emergency freezes and blacklists, creating about $236 million in possible secondary exposure while Arbitrum governance later secured roughly $71 million. The excerpt does not attribute the attack to DPRK, so the summary preserves the incident mechanics without adding unsupported actor claims.

Related Reports

« Back