Country visual unavailable
No information
The breach began on 6 March 2026 when an attacker socially engineered a LayerZero Labs developer, harvested session keys, entered LayerZero's RPC cloud and poisoned internal RPC nodes. On 18 April the attacker combined tampered RPC responses with a denial-of-service attack against an external RPC provider, causing the LayerZero Labs DVN to attest forged state used by KelpDAO's rsETH bridge and resulting in the loss of about USD 292 million; LayerZero reported attribution to DPRK-linked TraderTraitor/UNC4899.
Estimated severity
94 / 100
Source reliability
95 / 100
Approximate Date
06/03/2026
Targeted Company
LAYERZERO LABS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
$292M
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Please rotate your phone