According to LayerZero Labs' incident report released in May, the KelpDAO rsETH cross-chain bridge built on LayerZero's protocol was attacked beginning March 6, 2026, with approximately 116,500 rsETH (~$292 million) stolen. Security firms Mandiant and CrowdStrike attributed the attack to North Korean-linked hacker group TraderTraitor (UNC4899), which exploited social engineering to breach LayerZero developer accounts, compromised RPC cloud infrastructure, and manipulated node data to deceive monitoring systems and decentralized validator networks (DVN).
LayerZero Labs announced security strategy adjustments, including preventing its own DVN from serving as the sole signer in single-validator configurations. The company will rebuild affected cloud infrastructure and implement short-term credentials, immediate privilege escalation controls, and multi-party approval mechanisms.