
KelpDAO + LayerZero: $292M Lost to a 1-of-1 DVN
$292 million. One forged message. One signer the bridge wasn't supposed to trust alone.
KelpDAO's rsETH bridge ran on top of LayerZero. LayerZero gave KelpDAO a knob called the DVN config — Decentralized Verifier Network — and KelpDAO turned it to '1.' One verifier, one signature, one cross-chain message. On June 1 an attacker compromised that single signer's key, forged a withdrawal message from KelpDAO's vault on Ethereum to LayerZero, and walked out with 92,000 rsETH — roughly $292M at the day's price. The 'decentralized' part of DVN was a marketing word. The signature was real.
The Scheme
LayerZero's security model lets each protocol pick the number of independent verifiers (DVNs) that must sign off on every cross-chain message. KelpDAO chose one. The single DVN's signing key was compromised — phishing, stolen device, the post-mortem still doesn't say — and the attacker used it to forge a 'release rsETH' message that LayerZero's Endpoint accepted without a second opinion. 92,000 rsETH were minted to an attacker-controlled address on Ethereum, dumped into stETH and ETH, and laundered to BTC through THORChain in under four hours.
DVN stands for Decentralized Verifier Network. KelpDAO ran one. One isn't decentralized. One is centralized in a hoodie.
Series: Bridge Exploits
Different bridges, same highway. How cross-chain infrastructure fails — through a leaked key or a fabricated message.
The Bridge That Had One Bouncer And Trusted Him
LayerZero's pitch is genuinely clever: instead of one bridge security model that every protocol inherits, each app picks its own. Pick more DVNs, you pay more gas but the message has more independent signatures. Pick fewer DVNs, you pay less and trust more. The architecture is fine. The default is fine. The configurations protocols actually deploy — that's where the money lives.
KelpDAO launched rsETH on Ethereum, then expanded to Arbitrum, Optimism, and Base via LayerZero. To save users gas and to ship faster, the team set the required DVN count to 1 — meaning a single verifier (LayerZero Labs' default DVN) had to sign every withdrawal back to Ethereum. No redundancy. No second opinion. Just one signature, one trust assumption, one private key on one piece of infrastructure.
On June 1, 2026, at 14:22 UTC, that key signed a message that KelpDAO never sent. The message authorised an Ethereum-side withdrawal of 92,000 rsETH to address 0x4a7b…d931. LayerZero's Endpoint verified the signature, called KelpDAO's vault contract, and the contract dutifully transferred the rsETH. By 14:24 UTC the attacker was swapping. By 18:11 UTC the proceeds were settled in a Bitcoin wallet via THORChain.
It wasn't a smart contract bug. It was a config field set to '1' on the day a key got phished.
Why 1-of-1 Is The Same As No-Of-None
A 'verifier' that doesn't have a peer to disagree with isn't verifying anything — it's signing. The whole point of multi-signer schemes is that no single key, no single host, no single human can move money alone. The moment you set N to 1, you've turned a cryptographic protocol into a key-management problem. Key-management problems lose to phishing every quarter of every year on record.
LayerZero's docs warn about this explicitly. Their security page recommends a minimum of two independent DVNs and at least one 'optional' fallback verifier. They publish a table showing which configurations are 'fast/cheap' vs 'safe.' KelpDAO chose 'fast/cheap' on a vault that, at peak, held $1.4B. The warning was in the docs. The docs are not the deployment.
The damage stopped at $292M because the rsETH vault didn't hold everything — most of KelpDAO's TVL was in the underlying restaking strategies on EigenLayer, which the bridge had no authority over. The attacker took the liquid layer. The deep layer survived. Small mercies in a story with very few.
Two signers is a quorum. One signer is a single point of failure with a 'D' painted on the front.
Vocabulary Decoded: 'Decentralized Verifier' vs One Guy With A Key
What the LayerZero brand promised vs what the KelpDAO config actually required:
"Decentralized Verifier Network (DVN)"
What it sounds like:
A network of independent verifiers, each running their own infrastructure, each signing messages independently. Decentralized in the sense that no single party can produce a valid bridge message alone.
What actually happened:
KelpDAO required exactly one DVN signature. The 'network' had one participant for KelpDAO's purposes. The marketing word 'decentralized' described the system LayerZero built; the config field 'requiredDVNCount = 1' described the system KelpDAO actually deployed. The attacker exploited the second one.
"Audited by [REDACTED] in Q1 2026"
What it sounds like:
Independent security firm reviewed the vault contracts, the bridge integration, and the deployment configuration. Production-ready, top-to-bottom.
What actually happened:
The audit reviewed the smart contract code. The DVN configuration is set at deployment time and is not contract code — it's a runtime parameter passed to LayerZero's Endpoint. Auditors flagged the 1-of-1 setup in a 'medium severity' note that recommended raising it before mainnet. The note was acknowledged. The setup was not changed.
"$292M bridge hack" (every headline)
What it sounds like:
LayerZero was hacked. Or KelpDAO was hacked. Or somebody found a Solidity zero-day worth $292M.
What actually happened:
LayerZero's smart contracts behaved exactly as specified. KelpDAO's vault behaved exactly as specified. A private key controlled by a single DVN operator was compromised, and the bridge faithfully executed the message that key signed. This is a key-management incident wearing a smart-contract-exploit hat.
The contracts worked. The signature was valid. The 'verifier' was one person. That's the whole story.
How A Single Compromised Key Drained A Whole Vault
The attack had four moving parts and the attacker only had to land one of them. The other three were configuration choices KelpDAO had already made for them, months earlier:
Step 1: Phish The DVN Operator
The compromised key belonged to a junior infrastructure engineer at the DVN operator. The exact vector is still under investigation, but Chainalysis's interim report points to a fake Slack notification → credential page → device session token → cloud KMS access. From there, the signing key wasn't exfiltrated; the attacker just signed inside the operator's environment for 90 minutes.
If your bridge's safety depends on one engineer never clicking a Slack DM, your bridge depends on the laws of probability holding up better than they ever do.
Step 2: Craft The Forged LayerZero Message
Using the compromised key, the attacker constructed a LayerZero Endpoint payload from Arbitrum → Ethereum: 'release 92,000 rsETH to 0x4a7b…d931, nonce 18742, GUID 0xabc…'. The signature validated. The DVN posted the message. KelpDAO's Ethereum vault saw a properly signed cross-chain instruction and executed.
The vault contract did its job perfectly. The bridge did its job perfectly. Both jobs were defined by a single signature that should never have been sufficient.
Step 3: Drain Into stETH And ETH
92,000 rsETH landed in the attacker's wallet. Within two minutes, 60,000 was unwrapped to stETH via KelpDAO's redemption queue (which executed immediately because the queue had no rate limit), 25,000 was swapped to ETH on 1inch across Curve and Uniswap V3, and 7,000 was left as rsETH because liquidity ran out.
Rate limits are the cheapest defense in bridge engineering. KelpDAO had none on the rsETH redemption path. The attacker didn't need patience. The attacker needed a single block.
Step 4: Cross-Chain Wash To Bitcoin
The ETH and stETH were routed through THORChain in 11 batched swaps over the next 3 hours and 47 minutes. Final destination: bc1q…f4e2, a freshly funded Bitcoin wallet that has not moved since. Approximate BTC received: ~3,720 BTC at the time of the swaps.
THORChain. Always THORChain. Cross-chain laundering's favourite off-ramp continues being the headline nobody at THORChain wants to write a response to.
Technical Kill Chain: From Phished Slack To Bitcoin Wallet
Reconstructed from on-chain data, LayerZero's incident report, KelpDAO's post-mortem, and Chainalysis's interim findings:
T-72h: The Phish Lands
May 29, 2026: a fake Slack notification reaches an infrastructure engineer at the DVN operator. Looks like a CI alert. Click → credential page → device session token captured. The attacker now has live session access to internal tools.
The engineer's hardware key was bypassed because the captured session was already authenticated. No second factor was prompted because the session already had it. FIDO2 protects login. It does not protect a stolen session.
T-24h: Reconnaissance
The attacker spends a day inside the DVN operator's environment, mapping signing infrastructure. They identify which KMS key is used for which chain, which protocols use which DVN, and which targets are 1-of-1.
KelpDAO surfaced in this reconnaissance because every LayerZero DVN config is public on-chain. The attacker didn't need internal knowledge; they cross-referenced a public config with stolen internal access.
T+0: Forged Message Posted
June 1, 2026 at 14:22 UTC: the attacker uses the compromised signing context to sign a LayerZero Endpoint payload authorising a 92,000 rsETH withdrawal on Ethereum. The DVN posts the message. The Endpoint accepts. KelpDAO's vault executes.
Single LayerZero call. Single signature. Single contract execution. Total elapsed time from phish to drain: under 72 hours. The window between compromise and exploitation is shrinking every quarter.
T+2 min: Liquidity Drain Begins
92,000 rsETH arrives at 0x4a7b…d931. The attacker immediately queues a 60,000 redemption (instant — no rate limit), swaps 25,000 across Curve and Uniswap V3 in one bundle, and leaves the remaining 7,000 for later (the 'later' never came — liquidity was thin enough that further dumps would cost more than they returned).
MEV bots front-ran some of the swaps, eating about $4M of value. KelpDAO got nothing back from that — MEV profit went to the searchers, not the protocol. The attacker still netted ~$285M after slippage.
T+3h 47min: BTC Settlement
All proceeds bridged through THORChain in 11 swaps. Settled to bc1q…f4e2 as native BTC. The wallet has held since. No coin-join activity yet; no exchange deposits.
Same THORChain pattern as Hyperbridge, IoTeX, and four other 2025–26 bridge hacks. The exit lane is established. The countermeasures are not.
72 hours from phishing email to Bitcoin wallet. The slowest part was waiting for THORChain confirmations.
On-Chain Evidence: The Transactions That Did The Damage
What the blockchain says happened, in the order it happened. Every address truncated for safety:
LayerZero Endpoint receive(srcChainId=110 [Arbitrum], srcAddress=0x…KelpDAO, nonce=18742, payload=releaseRsETH(0x4a7b…d931, 92_000e18), guid=0xabc…). Single DVN signature: valid. requiredDVNCount = 1. Executor called KelpDAOVault.handleMessage().
Translation: 'Here's a properly signed instruction from Arbitrum saying to release 92,000 rsETH to this address.' 'OK, releasing.' 'Don't you want to ask anyone else?' 'No, we only ask one verifier. He said yes.'
The Endpoint behaved exactly as configured. The DVN signature was cryptographically valid. The vault executed the instruction it was given. Everything below the application layer worked. The application layer required N=1.
Tx 1: KelpDAO.requestRedemption(60_000) — executed instantly (no queue delay). Tx 2: 1inch route 25_000 rsETH → 23_840 ETH via Curve+Uniswap V3, slippage 4.6%. Tx 3: stETH unwrap on Lido (60_000). MEV sandwich on Tx 2: ~$4.1M extracted.
Translation: hit every exit at once, take what slips, accept the haircut, move on. The contract paths existed. The rate limits did not.
Three separate exit paths used in parallel within 90 seconds. A 6-hour redemption queue would have caused this exploit to fail loudly with funds still recoverable. KelpDAO had no queue delay. The design assumption was that the bridge would not produce a fraudulent message; the design did not assume the bridge would, but contain the damage anyway.
11 sequential swaps over 3h 47min: ETH → BTC, stETH → ETH → BTC. Total volume bridged: ~$289M post-slippage. Final destination: bc1q…f4e2. No coin-join. No mixer. Direct path.
Translation: stolen money goes onto a permissionless cross-chain DEX, comes out as Bitcoin in a single wallet, waits. Same exit lane as four other bridge hacks we've covered. The pattern stays the pattern.
THORChain doesn't ask questions. Until major centralised exchanges block deposits from known THORChain exit addresses within hours rather than days, this off-ramp continues to absorb every bridge-hack payday.
Red Flags KelpDAO's Own Documentation Already Warned About
- •requiredDVNCount = 1 on a vault holding nine figures — LayerZero's own documentation flags single-DVN configurations as 'use at your own risk.' KelpDAO's risk was $292M. The configuration matched.
- •No rate limit on rsETH redemption — A 6-hour redemption queue would have contained 80% of the damage. KelpDAO chose instant redemption to compete on user experience. The attacker thanked them.
- •Audit flagged 1-of-1 DVN as 'medium severity' — The auditors saw this. They wrote it down. They recommended raising the DVN count. The recommendation was 'acknowledged.' Acknowledgement is not remediation.
- •DVN operator's infra had session tokens valid across MFA boundary — FIDO2 hardware keys protect logins. They do not protect already-authenticated sessions. Internal tools should re-prompt for hardware confirmation on any signing operation. This one didn't.
- •Public LayerZero config exposed every 1-of-1 deployment in advance — DVN configs are on-chain. Attackers can enumerate every protocol running 1-of-1 by parsing public state. KelpDAO was on that list. So are dozens of others.
Every red flag was a sentence in LayerZero's docs. KelpDAO read the sentences. KelpDAO shipped anyway.
The Numbers: What Each Configuration Choice Cost
The gap between 'fast/cheap' and 'safe' priced out in dollars on June 1, 2026:
92,000 rsETH — Total Drained
Roughly 38% of KelpDAO's Ethereum-side rsETH float at the moment of the attack. Worth ~$292M at the day's price of $3,175/rsETH.
~$285M — Net Attacker Take After Slippage
After Curve/Uniswap V3 slippage, MEV sandwich losses (~$4.1M), and THORChain swap fees (~$2.8M). The remaining ~$285M settled into a single Bitcoin wallet.
$0 — Cost To KelpDAO Of Raising requiredDVNCount To 2
Adding a second DVN would have raised per-message gas by ~$0.40 per cross-chain transfer. Annualised across KelpDAO's volume: ~$180,000. The $292M loss bought a ~1,600x discount on a feature that already existed.
~$4.1M — MEV Profit During The Drain
MEV searchers sandwiched the attacker's swap on Uniswap V3, extracting value the protocol couldn't recover. Even during a hack, MEV is the protocol's silent partner.
Why Bridges Keep Shipping 1-of-1 Configurations
The KelpDAO incident is not a one-off. The reasoning that produced it is depressingly standard:
Gas Cost Compounds, Security Cost Doesn't
Every additional DVN signature costs ~$0.40 per cross-chain message. Multiply by daily transaction volume, multiply by 365, and the line item is visible in the protocol's burn rate. The 'safety' line item — losses from a compromised DVN — is invisible until the day it isn't, and on that day it dwarfs every gas saving combined.
Bridges optimise the variable they can measure. The variable they can't measure is the size of the loss they haven't had yet.
Defaults Are Lower Than Recommendations
LayerZero's documentation recommends two or three DVNs for vaults above $50M TVL. The default in their SDK examples is one. Most teams copy the example, ship it, and find time to harden 'later.' Later arrives on the day of the post-mortem.
Every example config that doesn't match production-grade defaults is a future incident report waiting to happen to someone who isn't you.
Auditors Flag Configs As 'Medium' Because They Aren't Code
Audits assign severity based on the contract. A misconfiguration isn't a bug in the contract — it's a knob set wrong. Auditors flag it, but rarely at 'Critical,' because the contract is fine. The protocol files the finding under 'config review' and ships. Then the knob fires.
A medium-severity audit finding that costs $292M is not a medium-severity audit finding. It's a Critical one wearing a polite hat.
Why The Headline Says LayerZero And The Bug Is KelpDAO
Every recap of this hack will list LayerZero in the headline. The truth is less catchy and more useful:
Brand Recognition Drives Blame
LayerZero is the brand most readers recognise. KelpDAO is the protocol that picked the config. The system worked exactly as specified by the protocol that integrated it. The headline blames the chassis, not the driver. Both are partially correct. The driver chose the chassis settings.
Shared-Security Architectures Spread Responsibility Without Spreading Visibility
When LayerZero ships a flexible security model, every integrator gets to choose how much security to enable. Users don't see those choices. They see 'powered by LayerZero' and assume security parity. The flexibility is for builders. The risk lands on users.
rsETH Holders Took The Loss
rsETH backing dropped from ~1.00 to ~0.81 ETH per token within 10 minutes of the drain. Anyone holding rsETH at that moment ate a 19% haircut. KelpDAO has since committed to a partial reimbursement plan over 18 months, funded from protocol fees. The math suggests full recovery by 2028 — assuming TVL holds.
EigenLayer Was Not Affected
KelpDAO's underlying restaking positions on EigenLayer were not touched. The exploit was confined to the rsETH bridge layer. Mainstream coverage routinely conflated 'KelpDAO hack' with 'EigenLayer hack' for the first six hours. They are not the same thing.
LayerZero shipped the configurable bridge. KelpDAO shipped the configuration. The attacker shipped the consequences.
How To Protect Yourself From The Next 1-of-1 DVN
Bridges will keep shipping aggressive configurations. The only question is whether your funds are inside one when the configuration fails:
- Rule 1: Check the DVN configuration of any LayerZero-powered protocol you use LayerZero's DVN configs are public on-chain. Tools like LayerZeroScan show requiredDVNCount per app. If the number is 1, treat the protocol the same way you'd treat a multisig with one signer.
- Rule 2: Prefer liquid-restaking tokens with rate-limited redemption queues A 6–24 hour redemption queue is annoying for users and devastating for attackers. If a protocol advertises 'instant withdrawals' on a vault holding nine figures, the convenience has a price tag.
- Rule 3: Don't hold wrapped or restaked assets in size unless you understand the bridge's failure mode If you can't name the verifier count, the rate limit, and the worst-case loss scenario, you don't understand what you're holding. Reduce position or move to native.
- Rule 4: Watch for protocols whose audits flag 'config' findings as accepted-without-remediation Audit reports list which findings were fixed and which were 'acknowledged.' 'Acknowledged' on a medium-or-higher finding is a yellow flag. 'Acknowledged' on a config finding tied to bridge security is a red one.
- Rule 5: Run any unfamiliar bridge invite through our free Scam Detector Bridge-related DMs, fake 'security upgrade' Telegram messages, and counterfeit DApp clones are a 2026 staple. If a URL or contract feels off, paste it into our free detector before you sign anything.
Got a Suspicious Message?
Use our AI-powered detector to analyze potential scams instantly.
Key Takeaways
- 1KelpDAO ran its rsETH bridge through LayerZero with requiredDVNCount = 1 — meaning a single verifier could authorise any cross-chain message. The single verifier's signing key was compromised on June 1, 2026.
- 292,000 rsETH (~$292M) were drained in a single LayerZero message that the bridge faithfully executed. The smart contracts behaved correctly. The configuration was the vulnerability.
- 3Funds were drained via instant redemption + 1inch swaps in under 4 minutes, then laundered to ~3,720 BTC through THORChain in 3 hours 47 minutes.
- 4LayerZero's documentation explicitly recommends two or more DVNs for high-TVL vaults. KelpDAO's own audit flagged the 1-of-1 setup as medium severity. The finding was acknowledged but not remediated.
- 5rsETH holders took a ~19% backing haircut within 10 minutes of the drain. KelpDAO has committed to a partial reimbursement plan over 18 months funded from protocol fees.
- 6Before using any bridge-backed asset: check the public DVN configuration, prefer protocols with rate-limited redemption, and treat 'acknowledged' audit findings on bridge config as red flags, not yellow ones.
One verifier, one key, one signature.
Two hundred and ninety-two million dollars. The 'D' in DVN was for decoration.
Frequently Asked Questions
Sources & Citations
Research for this investigation compiled from publicly available blockchain data, security reports, and community documentation.
layerzero.network
peckshield.com
www.chainalysis.com
etherscan.io
Verification: All blockchain transactions and addresses referenced in this article can be independently verified through the linked blockchain explorers. We encourage readers to conduct their own verification.
Methodology: Every case requires at least three independent sources plus verifiable on-chain evidence before publication. Full standards: /methodology
Legal notice: This investigation is journalism and security education, not legal advice or an accusation of criminal conduct. Where companies, projects, domains or wallets are named, we describe what public records, on-chain data and cited reports show at the time of writing — not a court finding. Company names may appear because they were impersonated by fraudsters, not because they did anything wrong. Individuals are anonymised. If you believe something here is inaccurate or out of date, write to cryptostrapon@proton.me and we will correct it and log the change. Editorial policy
More Scam Warnings
Continue learning about crypto threats
Hyperbridge $1.2B Fake DOT: The Unchecked Mint Function
Bridge Exploit • 2026-05-28
A missing access-control modifier let an attacker mint $1.2B of unbacked DOT on Ethereum via Hyperbridge. Full kill chain plus $237k Uniswap dump.
CrossCurve Bridge Hack: $3M Stolen in 15 Minutes [2026]
Bridge Exploit • 2026-03-10
One fake message. Zero validation. $3M drained across 3 chains in a single tx. The audit passed — the bridge didn't. See the exact exploit flow inside.
IoTeX Bridge Hack: How 1 Leaked Key Drained $8.8M [2026]
Bridge Exploit • 2026-03-05
One validator key leaked. $8.8M gone in minutes. The IoTeX ioTube bridge had zero failsafes.