LIVE NEWS
  • Award for scientist who brought space to millions
  • Ukraine officials name Zelenskyy’s ex-chief of staff as a suspect in money-laundering probe
  • Ray Dalio Says Bitcoin Fails as Safe Haven And Saylor Fired Back
  • Citrix moves secure access to a flexible, credit-based consumption model
  • Nvidia CEO Jensen Huang isn’t part of Trump’s China trip
  • US in closely guarded talks to open new bases in Greenland
  • This $30 Nuclear Stock Could Be Your Ticket to Millionaire Status
  • US, partner nations sink two decommissioned ships during Exercise Balikatan
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Crypto»LayerZero Admits Mistake in 1/1 DVN Setup Tied to $292M Kelp Hack
Crypto

LayerZero Admits Mistake in 1/1 DVN Setup Tied to $292M Kelp Hack

primereportsBy primereportsMay 9, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
LayerZero Admits Mistake in 1/1 DVN Setup Tied to 2M Kelp Hack
Share
Facebook Twitter LinkedIn Pinterest Email


LayerZero Labs acknowledged a Lazarus Group attack on internal RPCs and a multisig signer’s unauthorized personal trade, impacting 0.36% of assets on the protocol.

LayerZero on Friday issued a public apology for its handling of the April 18 exploit that drained roughly $292 million from Kelp DAO’s rsETH bridge, conceding it should not have allowed its own validator to operate as the sole verifier securing high-value transactions.

In a blog post which begins by stating “first things first: an overdue apology,” the interoperability protocol said its internal RPC nodes — used by the LayerZero Labs Decentralized Verifier Network (DVN) — were compromised by North Korea’s Lazarus Group, which “poisoned” their source of truth, while its external RPC provider was simultaneously hit by a DDoS attack. LayerZero said the underlying protocol itself was not affected.

“We believe developers should choose their own security configurations, but we made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions,” the company wrote. “We didn’t police what our DVN was securing, which created a risk we simply didn’t see. We own that.”

The incident impacted a single application — about 0.14% of applications built on LayerZero — and roughly 0.36% of the value of assets across the network, according to the post. LayerZero said more than $9 billion has moved across the protocol since April 19, the day after the exploit.

Previous Finger-Pointing

The apology is a shift from LayerZero’s earlier postmortem, which said the protocol “functioned exactly as intended” and pointed to Kelp’s manual configuration as the root cause. Kelp DAO publicly disputed that account, alleging LayerZero had approved the 1-of-1 DVN setup, and announced it would migrate its bridge infrastructure to Chainlink’s CCIP. Solv Protocol followed days later with plans to move more than $700 million in tokenized bitcoin tech off LayerZero.

LayerZero outlined a series of changes since April 19. The LayerZero Labs DVN no longer services 1/1 DVN configurations. Default settings on all pathways are being migrated to 5/5 where possible, with a minimum of 3/3 on chains where only three DVNs are available — a notable shift given that a recent Dune analysis found 47% of active LayerZero OApps still ran a 1-of-1 setup. The team is also building a second DVN client in Rust for client diversity and has reconfigured RPC quorums to mix internal, dedicated-external, and shared-external nodes.

Unreported Incident

The post also disclosed a separate, previously unreported incident from three and a half years ago, in which a multisig signer used the company’s multisig hardware wallet to execute a personal trade rather than a personal device. LayerZero said the signer was removed, wallets were rotated, and that the company has since added anomaly-detection software to signing devices.

LayerZero said it has built a custom multisig called OneSig and plans to raise its own multisig threshold from 3-of-5 to 7-of-10 across all supported chains. OneSig hashes transactions locally on the signer’s machine to prevent backend tampering, and each signer runs a private anomaly checker. The company said it is also rolling out Console, a platform for asset issuers to configure and monitor deployments, with built-in detection for unknown DVNs, ownership changes and unsafe configurations.

LayerZero said an official post-mortem will be published once its external security partners conclude their work. The hack also left Aave with an estimated $124 million to $230 million in bad debt, and a coalition of DeFi protocols has outlined a technical path to restore rsETH’s backing.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDirty Frag: Unpatched Linux vulnerability delivers root access
Next Article Iran War Live Updates: Lasting Truce Is Elusive After Week of Traded Attacks
primereports
  • Website

Related Posts

Crypto

Ray Dalio Says Bitcoin Fails as Safe Haven And Saylor Fired Back

May 12, 2026
Crypto

Morgan Stanley launches crypto price war on ETrade

May 11, 2026
Crypto

Crypto and AI Could Be Dirty Words on 2026 Campaign Trail

May 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20265 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Award for scientist who brought space to millions
  • Ukraine officials name Zelenskyy’s ex-chief of staff as a suspect in money-laundering probe
  • Ray Dalio Says Bitcoin Fails as Safe Haven And Saylor Fired Back
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.