Articles/Security, Hacks & Vulnerabilities·48d ago
Ingested articleSecurity, Hacks & Vulnerabilities

Kelp DAO $290 Million DeFi Hack Blamed on Single-Verifier Setup and Lazarus Group

20 Apr 2026 · 06:30 UTC · CoinCentral RSS Feed · Original source

Read original at CoinCentral RSS Feed

Summary

Kelp DAO suffered a $290–293 million exploit after attackers compromised RPC nodes used by LayerZero's verifier. LayerZero had previously warned Kelp to implement multiple verifiers, but the protocol continued operating a risky single-verifier configuration. North Korea's Lazarus Group has been preliminarily linked to the attack. The breach impacted at least nine DeFi protocols, including Aave, exposing broader vulnerabilities in the DeFi infrastructure ecosystem and the dangers of relying on single points of failure in critical verification systems.

Market Impact analysis

Why it matters

The hack represents a major operational failure in critical DeFi infrastructure and validates existing concerns about protocol design flaws. Immediate mechanisms driving losses: (1) Direct balance sheet impacts on nine protocols; (2) Panic liquidations as users withdraw from affected platforms; (3) Contagion across integrated protocols; (4) Reduced confidence in decentralized verification models. The preliminary Lazarus Group attribution (if confirmed) indicates sophisticated targeting of high-value infrastructure and elevates geopolitical risk perception. Altcoins are disproportionately affected because DeFi represents a core use case, whereas Bitcoin benefits less directly from DeFi ecosystem health. Medium-term recovery depends on protocol speed implementing security patches, maintaining user confidence, and regulatory clarity. Key uncertainties: (1) Final attribution confirmation; (2) Magnitude of cascading liquidations; (3) Regulatory response timeline; (4) Whether architectural fixes are sufficient to restore confidence.

Expected impact

The $290+ million Kelp DAO hack will trigger immediate negative sentiment across cryptocurrency markets, with severe cascading effects on the DeFi ecosystem. Altcoins face sharper declines due to direct exposure to affected protocols and loss of confidence in DeFi security architecture. The single-verifier failure demonstrates systemic architectural weaknesses, elevating perceived risk across the sector. Affected protocols (including Aave and eight others) will experience capital outflows and liquidation cascades. Bitcoin may initially see modest flight-to-safety inflows but will ultimately follow broader market weakness from crypto sentiment deterioration. Panic liquidations will amplify short-term volatility. Over 1-2 weeks, sentiment may stabilize as protocols implement emergency fixes and communicate remediation plans. Within a month, market focus will shift to regulatory implications and structural DeFi improvements, enabling partial recovery. Long-term damage to DeFi trust and potential regulatory crackdowns pose extended headwinds.

Kelp DAO $290 Million DeFi Hack Blamed on Single-Verifier Setup and Lazarus Group | Market Impact