BTC $80,703.98 +3.54%
ETH $2,508.17 +4.01%
BNB $715.04 +2.14%
XRP $1.44 +5.03%
SOL $103.53 +2.66%
TRX $0.3279 +0.52%
DOGE $0.0869 +4.36%
ADA $0.2209 +6.93%
BCH $256.39 +2.15%
LINK $11.92 +6.17%
HYPE $86.12 +4.80%
AAVE $133.90 +4.29%
SUI $0.7698 -0.49%
XLM $0.1835 +3.73%
ZEC $969.55 +16.58%
BTC $80,703.98 +3.54%
ETH $2,508.17 +4.01%
BNB $715.04 +2.14%
XRP $1.44 +5.03%
SOL $103.53 +2.66%
TRX $0.3279 +0.52%
DOGE $0.0869 +4.36%
ADA $0.2209 +6.93%
BCH $256.39 +2.15%
LINK $11.92 +6.17%
HYPE $86.12 +4.80%
AAVE $133.90 +4.29%
SUI $0.7698 -0.49%
XLM $0.1835 +3.73%
ZEC $969.55 +16.58%

The process of the KelpDAO attack analyzed by Slow Fog

2026-04-20 13:15:43

According to SlowMist founder Yu Xian (@evilcos), the core of the KelpDAO theft incident, which involved approximately $290 million, was a targeted poisoning attack on the downstream RPC infrastructure of LayerZero DVN (Decentralized Validator Network).

The specific attack steps were: first, obtaining the list of RPC nodes used by LayerZero DVN, then breaching two independent clusters and replacing the op-geth binary file; using selective deception techniques to return forged malicious payloads only to DVN while returning real data to other IPs; simultaneously launching DDoS attacks on the unbreached RPC nodes, forcing DVN to failover to the poisoned nodes, completing the forged message verification, and then the malicious binary self-destructing and clearing logs. This ultimately led to LayerZero DVN issuing validations for "transactions that never occurred."

app_icon
ChainCatcher Building the Web3 world with innovations.