Lazarus strikes again: massive crypto heist exposes layerzero vulnerabilities
North Korean hackers, operating under the Lazarus Group, have launched another devastating attack, siphoning over $250 million in cryptocurrency from a popular online investment platform – a blow that underscores the escalating threat to the digital asset ecosystem.
A torrent of losses: the kelpdao breach
The assault, which occurred in April 2026, targeted KelpDAO, extracting more than 290 million dollars (approximately $250 million USD) in a token representing Ethereum (ETH) – specifically, rsETH – leaving LayerZero scrambling to identify the root cause. Initial investigations point to a sophisticated state-sponsored operation, strongly linked to the Lazarus Group’s established history of cybercrime.
This represents the largest cryptocurrency heist of 2026 to date, a chilling escalation in the ongoing campaign of financial disruption. The stolen funds, estimated at 116,500 rsETH, translate to roughly 124,600 ETH or 3,730 BTC – a substantial sum indicative of a highly organized and persistent adversary.

The ‘collateral’ gambit
What’s particularly alarming is the technique employed: a ‘collateral’ laundering scheme. The hackers leveraged Aave v3 and Wrapped Ether (WETH) protocols to generate a massive debt, effectively using the stolen funds as collateral to acquire further assets. LayerZero’s official statement chillingly labels this as “a highly sophisticated state-sponsored actor.”

Expert assessment: a pattern emerges
Industry analysts, including Henri Arslanian of Nine Blocks Capital Management, concur: “The attack’s signature is undeniably that of the Lazarus Group. Their modus operandi is consistently identifiable, a disturbing testament to their expertise and resources.” The group’s documented involvement in previous large-scale cryptocurrency thefts – including incidents at WazirX and DMM Bitcoin in 2024 – reinforces this assessment.
The fact that no contagion has been reported across other platforms offers a temporary reprieve, but it’s a fragile one. CoinDesk has definitively categorized this incident as ‘the biggest crypto cyberattack of 2026,’ a stark warning to the industry about the need for rigorous security protocols.

Beyond the immediate damage
While the immediate impact appears contained, the incident highlights the vulnerability of decentralized finance (DeFi) protocols and the potential for exploitation through sophisticated manipulation. Kyber, a notorious hacking group, is already reportedly experimenting with post-quantum cryptography on Windows – a development that further complicates the security landscape. The continued activity of the Lazarus Group underscores a dangerous trend: the relentless pursuit of illicit financial gain through digital means.
