LIVE NEWS
  • Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited
  • I Don’t Know If This Was Our Last Family Vacation
  • Agentic-AI tool aims to give US commanders new target options ‘within seconds’
  • AeroVironment Q4 2026 Earnings Preview
  • In a Taiwan war, forces would need Darwin for medical support. We’re not preparing it
  • James Webb uncovers exotic salt clouds on a mysterious pink world
  • Israel moves to formally recognize Armenian WWI deaths as a genocide
  • Google Gemini AI Predicts Jaw-Dropping Bitcoin Price by Next 90 Days
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Crypto»LayerZero Admits Mistake in 1/1 DVN Setup Tied to $292M Kelp Hack
Crypto

LayerZero Admits Mistake in 1/1 DVN Setup Tied to $292M Kelp Hack

primereportsBy primereportsMay 9, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
LayerZero Admits Mistake in 1/1 DVN Setup Tied to 2M Kelp Hack
Share
Facebook Twitter LinkedIn Pinterest Email


LayerZero Labs acknowledged a Lazarus Group attack on internal RPCs and a multisig signer’s unauthorized personal trade, impacting 0.36% of assets on the protocol.

LayerZero on Friday issued a public apology for its handling of the April 18 exploit that drained roughly $292 million from Kelp DAO’s rsETH bridge, conceding it should not have allowed its own validator to operate as the sole verifier securing high-value transactions.

In a blog post which begins by stating “first things first: an overdue apology,” the interoperability protocol said its internal RPC nodes — used by the LayerZero Labs Decentralized Verifier Network (DVN) — were compromised by North Korea’s Lazarus Group, which “poisoned” their source of truth, while its external RPC provider was simultaneously hit by a DDoS attack. LayerZero said the underlying protocol itself was not affected.

“We believe developers should choose their own security configurations, but we made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions,” the company wrote. “We didn’t police what our DVN was securing, which created a risk we simply didn’t see. We own that.”

The incident impacted a single application — about 0.14% of applications built on LayerZero — and roughly 0.36% of the value of assets across the network, according to the post. LayerZero said more than $9 billion has moved across the protocol since April 19, the day after the exploit.

Previous Finger-Pointing

The apology is a shift from LayerZero’s earlier postmortem, which said the protocol “functioned exactly as intended” and pointed to Kelp’s manual configuration as the root cause. Kelp DAO publicly disputed that account, alleging LayerZero had approved the 1-of-1 DVN setup, and announced it would migrate its bridge infrastructure to Chainlink’s CCIP. Solv Protocol followed days later with plans to move more than $700 million in tokenized bitcoin tech off LayerZero.

LayerZero outlined a series of changes since April 19. The LayerZero Labs DVN no longer services 1/1 DVN configurations. Default settings on all pathways are being migrated to 5/5 where possible, with a minimum of 3/3 on chains where only three DVNs are available — a notable shift given that a recent Dune analysis found 47% of active LayerZero OApps still ran a 1-of-1 setup. The team is also building a second DVN client in Rust for client diversity and has reconfigured RPC quorums to mix internal, dedicated-external, and shared-external nodes.

Unreported Incident

The post also disclosed a separate, previously unreported incident from three and a half years ago, in which a multisig signer used the company’s multisig hardware wallet to execute a personal trade rather than a personal device. LayerZero said the signer was removed, wallets were rotated, and that the company has since added anomaly-detection software to signing devices.

LayerZero said it has built a custom multisig called OneSig and plans to raise its own multisig threshold from 3-of-5 to 7-of-10 across all supported chains. OneSig hashes transactions locally on the signer’s machine to prevent backend tampering, and each signer runs a private anomaly checker. The company said it is also rolling out Console, a platform for asset issuers to configure and monitor deployments, with built-in detection for unknown DVNs, ownership changes and unsafe configurations.

LayerZero said an official post-mortem will be published once its external security partners conclude their work. The hack also left Aave with an estimated $124 million to $230 million in bad debt, and a coalition of DeFi protocols has outlined a technical path to restore rsETH’s backing.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDirty Frag: Unpatched Linux vulnerability delivers root access
Next Article Iran War Live Updates: Lasting Truce Is Elusive After Week of Traded Attacks
primereports
  • Website

Related Posts

Crypto

Google Gemini AI Predicts Jaw-Dropping Bitcoin Price by Next 90 Days

June 28, 2026
Crypto

How does Pi mining work? The tech behind the tap

June 28, 2026
Crypto

Binance Sees $400M in Weekly Net Outflows Before MiCA Deadline

June 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Cybersecurity
  • Popular Now
  • Crypto
  • Artificial Intelligence
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited
  • I Don’t Know If This Was Our Last Family Vacation
  • Agentic-AI tool aims to give US commanders new target options ‘within seconds’
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.