LayerZero Labs, the team behind the LayerZero cross-chain messaging protocol, has issued what it calls an “overdue apology” for its handling of communications around the recent KelpDAO rsETH exploit and related security incident. Over roughly three weeks following the April 18, 2026 exploit of KelpDAO for about $290 million, attributed in incident reports to North Korea-linked Lazarus Group/TraderTraitor, LayerZero focused on preparing a full post‑mortem and gave limited public updates, prompting criticism from users and partners. In its new statement, LayerZero admits it “did a terrible job on comms,” accepts responsibility for missteps in how its infrastructure was configured and supervised, and acknowledges that this communication gap contributed to a loss of trust and the departure of some clients to competitors. Substantively, the apology clarifies that the LayerZero protocol itself was not compromised, but an internal RPC used by the LayerZero Labs Decentralized Verifier Network (DVN) was “poisoned” by Lazarus while an external RPC provider was simultaneously hit by a DDoS attack, allowing forged cross‑chain messages to be validated in KelpDAO’s rsETH setup. LayerZero concedes it made a serious error by allowing its own DVN to operate as a single‑verifier (1/1) configuration on high‑value flows, creating a single point of failure and enabling the attack path tied to the KelpDAO exploit. The team stresses that the impact was isolated to one application—about 0.14% of apps and 0.36% of asset value on LayerZero—and that no broader contagion occurred across other LayerZero-based assets or applications. The apology is paired with a set of corrective measures aimed at rebuilding confidence in LayerZero’s security model and governance. LayerZero says its DVN will no longer support 1/1 configurations for sensitive use cases and is shifting defaults toward multi‑verifier setups (e.g., 3‑of‑3) to eliminate single points of failure. It is also working with external security partners on a full post‑mortem, building a second DVN client (in Rust), rolling out a unified management platform with anomaly detection, and migrating key paths to stronger multisig setups such as 5/5 or 3/3, supported by its bespoke OneSig system. Additionally, the team is committing to more active developer education and configuration oversight, advising integrators to pin configurations, increase block confirmations, and use at least two‑party DVNs or run their own DVNs to harden security. The episode matters for the broader cross‑chain ecosystem because it highlights how misconfigured verifier networks and opaque incident communication can undermine otherwise sound protocol designs, and underscores a shift toward more opinionated defaults and operational safeguards in modular security architectures. "entities":["LayerZero","LayerZero Labs","LayerZero protocol","LayerZero Decentralized Verifier Network (DVN)","KelpDAO","rsETH","Lazarus Group","TraderTraitor","OneSig","KelpDAO exploit","Lazarus attack","ZRO token (LayerZero)"]}'}Note: The above output appears to be mistakenly wrapped in code fences and extra characters. Here is the corrected JSON response, properly formatted without code fences or extraneous text:{

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on LayerZero

Comments