Hackers drained $290 million from Kelp DAO over the weekend. LayerZero says preliminary indicators point to TraderTraitor, a hacking group tied to North Korea, and that attackers exploited LayerZero’s cross‑chain bridge together with Kelp DAO’s permissive approvals to move funds; Kelp DAO has disputed the attribution.

How the theft happened

Over a single weekend, attackers emptied more than $290 million in crypto from Kelp DAO, a protocol that lets users earn yield on otherwise idle assets. LayerZero, which provides a bridge that lets different blockchains send instructions to each other, said the attackers leveraged that bridge to issue fraudulent requests.

LayerZero said Kelp DAO’s internal security settings did not require multiple verifications before approving transactions, and that gap allowed the attackers to sign off on transfers that moved funds out of the protocol.

In broad strokes:

  • A cross‑chain message arrived via the LayerZero bridge.
  • The message triggered Kelp DAO’s approval flow.
  • Because the protocol accepted the instruction without additional confirmations, assets were released and moved out of Kelp DAO.

Who’s accused

LayerZero’s public post named a North Korea‑linked hacking group known as TraderTraitor as a likely actor, citing what it described as "preliminary indicators." The company framed those indicators as the basis for blaming the Democratic People’s Republic of Korea; Kelp DAO pushed back, disputing the assignment of blame immediately after the theft.

The accusation sits within a broader pattern of crypto‑targeted thefts that the industry has in recent years linked to actors tied to Kim Jong Un’s regime. LayerZero noted those groups have become adept at moving large sums of digital assets into channels that make recovery difficult.

Where this sits in 2026’s crime tally

The $290 million loss is the largest single crypto theft so far this year, edging past an early‑April breach that took roughly $285 million from the exchange Drift. Analysts and market participants were already jittery after that earlier incident; the Kelp DAO attack adds another large headline in quick succession.

LayerZero’s post also placed the Kelp DAO incident in a longer timeline, noting North Korea‑linked actors were believed to have stolen more than $2 billion in crypto last year and roughly $6 billion since 2017. Those cumulative figures inform conversations about custodial practices and cross‑chain security.

What this means for bridges and yield protocols

Cross‑chain bridges let assets and instructions move between otherwise separate blockchains, but that connectivity expands the attack surface. If a message that appears legitimate can be delivered across chains and then acted on without extra checks, a single vulnerability can cascade into a multi‑chain loss.

Yield protocols like Kelp DAO add complexity because they often automate transactions to capture small market edges. Automation speeds returns but reduces human friction; when security configurations accept a single approval path rather than multi‑party confirmation, automation that helps users earn yield can also let attackers clear out pools quickly.

Related Articles

LayerZero described the link to TraderTraitor as based on "preliminary indicators." Kelp DAO disputes that attribution while investigations continue.

This article was created with AI assistance.