BTC $62,960.60 -0.10%
ETH $1,878.23 -0.28%
BNB $606.04 -0.21%
XRP $0.9997 -0.45%
SOL $75.26 -0.29%
TRX $0.3310 -0.47%
DOGE $0.0695 -0.89%
ADA $0.1761 -2.37%
BCH $203.32 -0.97%
LINK $9.46 -0.88%
HYPE $56.88 +0.82%
AAVE $85.98 -0.62%
SUI $0.6738 -1.66%
XLM $0.1568 -1.43%
ZEC $484.79 -2.19%
BTC $62,960.60 -0.10%
ETH $1,878.23 -0.28%
BNB $606.04 -0.21%
XRP $0.9997 -0.45%
SOL $75.26 -0.29%
TRX $0.3310 -0.47%
DOGE $0.0695 -0.89%
ADA $0.1761 -2.37%
BCH $203.32 -0.97%
LINK $9.46 -0.88%
HYPE $56.88 +0.82%
AAVE $85.98 -0.62%
SUI $0.6738 -1.66%
XLM $0.1568 -1.43%
ZEC $484.79 -2.19%

The process of the KelpDAO attack analyzed by Slow Fog

2026-04-20 13:15:43

According to SlowMist founder Yu Xian (@evilcos), the core of the KelpDAO theft incident, which involved approximately $290 million, was a targeted poisoning attack on the downstream RPC infrastructure of LayerZero DVN (Decentralized Validator Network).

The specific attack steps were: first, obtaining the list of RPC nodes used by LayerZero DVN, then breaching two independent clusters and replacing the op-geth binary file; using selective deception techniques to return forged malicious payloads only to DVN while returning real data to other IPs; simultaneously launching DDoS attacks on the unbreached RPC nodes, forcing DVN to failover to the poisoned nodes, completing the forged message verification, and then the malicious binary self-destructing and clearing logs. This ultimately led to LayerZero DVN issuing validations for "transactions that never occurred."

app_icon
ChainCatcher Building the Web3 world with innovations.