Scan to download
BTC $60,605.07 -0.45%
ETH $1,552.40 -2.01%
BNB $573.75 +0.38%
XRP $1.07 -2.34%
SOL $61.61 -3.74%
TRX $0.3224 +0.18%
DOGE $0.0806 -1.02%
ADA $0.1569 -2.26%
BCH $213.92 -1.70%
LINK $7.31 -0.84%
HYPE $56.22 -5.14%
AAVE $59.94 -1.70%
SUI $0.7045 +0.51%
XLM $0.2037 +4.19%
ZEC $348.96 +0.28%
BTC $60,605.07 -0.45%
ETH $1,552.40 -2.01%
BNB $573.75 +0.38%
XRP $1.07 -2.34%
SOL $61.61 -3.74%
TRX $0.3224 +0.18%
DOGE $0.0806 -1.02%
ADA $0.1569 -2.26%
BCH $213.92 -1.70%
LINK $7.31 -0.84%
HYPE $56.22 -5.14%
AAVE $59.94 -1.70%
SUI $0.7045 +0.51%
XLM $0.2037 +4.19%
ZEC $348.96 +0.28%

The process of the KelpDAO attack analyzed by Slow Fog

2026-04-20 13:15:43
Collection

According to SlowMist founder Yu Xian (@evilcos), the core of the KelpDAO theft incident, which involved approximately $290 million, was a targeted poisoning attack on the downstream RPC infrastructure of LayerZero DVN (Decentralized Validator Network).

The specific attack steps were: first, obtaining the list of RPC nodes used by LayerZero DVN, then breaching two independent clusters and replacing the op-geth binary file; using selective deception techniques to return forged malicious payloads only to DVN while returning real data to other IPs; simultaneously launching DDoS attacks on the unbreached RPC nodes, forcing DVN to failover to the poisoned nodes, completing the forged message verification, and then the malicious binary self-destructing and clearing logs. This ultimately led to LayerZero DVN issuing validations for "transactions that never occurred."

app_icon
ChainCatcher Building the Web3 world with innovations.