# April 18 LayerZero Incident: Additional Context Source: https://x.com/kelpdao/status/2046332070277091807?s=46 ## Summary On April 18, rsETH was drained from its bridging adapter through a forged cross-chain message, according to Kelp, which published this follow-up while the broader post-incident review continues. Kelp says two RPC nodes hosted by LayerZero were compromised and a simultaneous DDoS attack targeted a third, and it states that Kelp's own systems were not involved in building or operating that infrastructure. Kelp says it paused relevant contracts on Ethereum mainnet and L2s, blacklisted wallets linked to the exploiter, and engaged SEAL-911, fully mitigating a follow-up attempt to target an additional 40,000 rsETH (~$95M). Kelp also states its 1-of-1 DVN setup is the default LayerZero documents for new OFT deployments. ## Article On April 18, rsETH was drained from rsETH bridging adapter through a forged cross-chain message. We want to ensure users and partners have the complete picture as the broader post-incident review continues. What happened. Two RPC nodes hosted by LayerZero were compromised. A simultaneous DDoS attack was launched against the 3rd RPC node. This was an attack on LayerZero's infrastructure. Kelp's own systems were not involved in building or operating that infrastructure. Kelp’s response helped contain the situation Kelp detected the anomaly, paused all relevant contracts on Ethereum mainnet and L2s, blacklisted all wallets associated with the exploiter, and engaged SEAL-911. A subsequent attempt by the exploiter, leveraging a falsely verified phantom packet to target an additional 40,000 rsETH (~$95M), was fully mitigated by these interventions. On the DVN configuration The 1-of-1 DVN setup is the configuration documented in LayerZero's documentation and shipped as the default for any new OFT deployment. Kelp has operated on LayerZero infrastructure since January 2024 and has maintained an open communication channel with the LayerZero team throughout. The question of DVN configuration came up during Kelp's L2 expansion, and defaults were affirmatively confirmed as appropriate at that time. Establishing a shared and accurate account of what happened is the foundation for making the right fixes together. The path forward Kelp’s priority is our users and preventing contagion across DeFi. We are working with all ecosystem partners to analyse the impact, rally support, and explore all avenues of mitigation. We are concurrently assessing the potential next steps regarding protocol unpausing, impact assessment, and the way forward, and working with Aave, LZ, and all other key stakeholders. ## Comments **timdaub.eth**: lol great minds think alike: https://news.kiwistand.com/stories/April-18-LayerZero-Incident-Additional-Context?index=0x69e6998839409818bdef4fe5954ae1dca2ca9e0124dd8eb91581a643bc3a7fdf975358d2 Not sure why the duplicate wasn‘t caught by Kiwi this time **mishaderidder.eth**: The difference is behind the question mark: https://x.com/kelpdao/status/2046332070277091807?s=12 https://x.com/kelpdao/status/2046332070277091807?s=46 **timdaub.eth**: Strange that it didn‘t catch that, because by resolving the canonical URL it should 🤔