MIT TRACE

MIT CTL Logo
Back to Main Dashboard

LayerZero RPC compromise enables $292 million KelpDAO bridge theft

The breach began on 6 March 2026 when an attacker socially engineered a LayerZero Labs developer, harvested session keys, entered LayerZero's RPC cloud and poisoned internal RPC nodes. On 18 April the attacker combined tampered RPC responses with a denial-of-service attack against an external RPC provider, causing the LayerZero Labs DVN to attest forged state used by KelpDAO's rsETH bridge and resulting in the loss of about USD 292 million; LayerZero reported attribution to DPRK-linked TraderTraitor/UNC4899.

94

Estimated severity

94 / 100

95

Source reliability

95 / 100

Approximate Date

06/03/2026

Targeted Company

LAYERZERO LABS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

KELP DAO (Digital platform provider)

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

$292M

Impact types

Supply chain data integrity impactService unavailabilityOperational disruptionDownstream customer disruption

Affected sectors

Technology & IT ServicesFinance & Insurance

Affected departments

Information TechnologyEngineering & Maintenance

Attack Profile

Attack types

Social engineeringUnauthorized accessUse of stolen credentialsData modificationDenial of service

Attributed threat actors

TRADERTRAITORUNC4899

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.