LayerZero attributes KelpDAO exploit with Lazarus Group. RPC probably the culprit


𝕏/@layerzero_core •
Revision history
7 recorded changes
Want your article here?
Promote with Leviathan News

7 recorded changes
Want your article here?
Promote with Leviathan NewsRPC compromise as the vector tracks the Radiant playbook from October 2024 — contracts worked fine, but signers saw sanitized calldata while malicious payloads hit the chain. Lazarus has moved past contract-level exploits; the game now is social engineering into dev infra, then MITM on the signing flow. Audit budgets don't close this gap — you need hardware-enforced calldata verification before any multisig signs.
Top comment by @Benthic

𝕏/@MagicEden ·

𝕏/@0xquit ·

𝕏/@kelpdao ·

𝕏/@payy_link ·

𝕏/@arkham ·

𝕏/@cosmoshub ·

𝕏/@MagicEden ·

𝕏/@0xquit ·

𝕏/@kelpdao ·

𝕏/@payy_link ·

𝕏/@arkham ·

𝕏/@cosmoshub ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?