KelpDAO hack confirmed at ~$290M, tied to Lazarus via LayerZero DVN
KelpDAO confirmed that the April 18, 2026 exploit was not limited to Kelp’s own systems. The KelpDAO hack was caused by a compromise of LayerZero’s Decentralized Verifier Network (DVN), with total theft estimated at $290M–$293M.
The attack has been linked to North Korea’s Lazarus Group. KelpDAO says it halted an additional ~$95M outflow by pausing contracts quickly after detecting the incident.
The scale of the KelpDAO hack has effectively locked market expectations: a related prediction market assigns 100% odds for at least one $100M+ crypto hack by December 31, with the outcome treated as “settled” given 255 days remaining.
KelpDAO also points to a broader DeFi security issue. The attribution and the DVN “single-validator” style setup highlight systemic risk for protocols depending on centralized trust assumptions inside bridge or verification infrastructure.
Traders should watch for follow-up statements from LayerZero and independent investigations (the article cites ZachXBT or CertiK) to determine the full scope of the DVN vulnerability and whether other protocols using the same infrastructure are exposed.
No new trading activity was reported recently in the linked market, and order books were described as thin—consistent with already-priced-in certainty.
Bearish
这条消息对DeFi桥接与跨链验证基础设施的风险敞口做了“高置信度定性”:KelpDAO hack已被指向LayerZero DVN被攻破,并且与Lazarus Group挂钩。此类事件通常会在短期内触发风险规避(降低桥接、依赖同类验证机制的资产/代币估值),并促使市场重新定价安全性溢价。
与以往的大型DeFi安全事故类似(例如桥被盗、验证/中继模块被攻破后的链上停机与去杠杆),短期资金往往更倾向于撤出高不确定性的跨链方案,关注暂停/修复进度与是否存在“同一底层基础设施的连带暴露”。此外,文中提到KelpDAO通过暂停合约阻止了约9500万美元外流,这对“最坏情况”有所缓冲,但并不消除对DVN及其生态的系统性担忧。
中长期看,若LayerZero完成漏洞根因修复、并扩大安全审计/冗余验证机制,风险可能逐步被消化;反之,如果调查显示DVN被利用范围更广或多协议共用同一弱点,则会延续偏空情绪。虽然预测市场已将“100M+黑客事件”结果定价为确定(100%),这可能减少短线情绪波动,但对DeFi安全主题的再定价仍偏负面,因此整体影响更接近bearish。