← Back to Blog

DPRK Hacks Kelp DAO: Inside Lazarus Group's Restaking Heist on Ethereum

One of Ethereum's largest restaking protocols was drained. The split pattern, the bridge route, and the BTC end-state all point to one operator: Lazarus. Here is the forensic breakdown.

Kelp DAO DPRK Lazarus laundering trail showing rsETH drained, swapped on Uniswap and CoW, mixed and bridged to BTC OTC off-ramps

Kelp DAO, one of the largest liquid restaking protocols on Ethereum, was compromised in an incident that is producing an on-chain forensic signature consistent with the established attack pattern of Lazarus Group, the elite cyber unit operating under North Korea's Reconnaissance General Bureau (RGB). The exploit follows the same operational template the DPRK has used to drain over $5 billion across Ronin, Atomic Wallet, Stake.com, CoinEx, HTX, WazirX, Radiant Capital, and the headline-grabbing $1.5B Bybit cold-wallet drain in February 2025.

This article is the focused forensic breakdown of the Kelp DAO incident. For the parallel breakdown of the Drift Protocol perpetuals exploit, see DPRK Hacks Drift Protocol.

Forensic Note

Attribution of crypto theft to specific nation-state actors is never made on a single signal. It is a multi-source assessment combining on-chain laundering pattern, malware family fingerprints, infrastructure overlap with prior campaigns, recipient-cluster reuse, and the timing and behavioral cadence of the attacker. The Kelp DAO incident registers against multiple of these axes simultaneously.


The 60-Second Summary

  • Initial vector was operational, not contractual. Preliminary indicators point to compromise of a privileged role — potentially a deployer key, an upgrade-admin signer, or an oracle update authority — rather than a smart-contract bug.
  • Drain executed in under an hour. Stolen ETH-denominated value was decomposed into ETH and stablecoin lots and split across multiple intermediary wallets within the first hour.
  • The bridging route is the tell. THORChain plus eXch is the same combination Lazarus has used since the Atomic Wallet incident.
  • Cascading damage beyond Kelp. Because rsETH is collateral in many other protocols, the blast radius extended into lending markets and structured-yield vaults that never held the stolen funds directly.
  • Recovery is partial but possible. Stablecoin issuers, bridge operators, and centralized exchanges can still freeze tagged deposits during the first 12 to 72 hours.

Why Kelp DAO Fits the Lazarus Target Profile

Restaking protocols are a near-perfect match for the DPRK target selection logic:

  • Massive concentrated TVL. Kelp DAO sits behind a small number of admin keys, signer multisigs, and upgrade authorities. A single compromise unlocks pooled deposits from thousands of users.
  • Atomic, irreversible withdrawals. Unlike a centralized exchange, there is no operations team to pause withdrawals, no compliance desk to issue a real-time freeze. Once a privileged transaction lands, it is final.
  • Composable collateral. rsETH is integrated into other protocols as collateral, which means an attack on Kelp causes secondary damage Kelp itself does not control. This amplifies the operational payoff per spear-phishing campaign.
  • Identifiable contributor team. Public-facing protocols with named engineering and ops contributors are exactly the LinkedIn-and-Telegram surface Lazarus operators target.

What Appears to Have Happened

Initial indicators suggest the Kelp DAO incident fits the operational-compromise pattern rather than a pure smart-contract exploit. The attacker appears to have obtained access to a privileged role — potentially a deployer key, an upgrade-admin signer, or an oracle update authority — and used it to execute actions that allowed unauthorized withdrawals from the protocol's collateral pool.

PHASE 01

Initial Access via Spear-Phishing

Weeks before drain

The dominant Lazarus initial-access vector since 2023 is the fake job offer. Operators pose as recruiters from real or fabricated companies on LinkedIn, Telegram, or Discord. The conversation moves to a "coding interview" or "take-home assignment" that delivers malware — commonly InvisibleFerret, BeaverTail, or a Python-based loader — the moment the target runs the supplied code.

The malware exfiltrates browser-stored secrets, AWS and 1Password credentials, signed commits, and any locally accessible private keys or seed material.

PHASE 02

Privilege Discovery

Days to weeks

Once inside the target environment, the attacker maps every privileged credential they can reach: AWS keys, GitHub access, internal Slack, deployer wallet seeds, signer keys, oracle admin credentials. Lazarus is patient. The Bybit incident showed them sitting on access for weeks before executing.

PHASE 03

The Drain Transaction

Single block

With the privileged credential in hand, the attacker submits the transaction permitted by that role with the highest payout — in this case, an action that allowed unauthorized withdrawals from the rsETH-backing collateral pool. The contract behaved exactly as designed. The attacker just had the key.


The Restaking Blast Radius: Why This Is Bigger Than Kelp

This is the single most important thing to understand about the Kelp DAO incident: the damage does not stop at Kelp.

Liquid restaking tokens are increasingly used as collateral across other lending protocols, perpetuals DEXs, and structured-yield vaults. A successful drain at the issuer level — Kelp DAO in this case — can trigger:

  • Cascading liquidations in lending markets where rsETH is posted as collateral, as the rsETH price decouples from underlying ETH.
  • Oracle de-pegs on rsETH price feeds, freezing or distorting positions across DeFi.
  • Frozen collateral in vaults that held rsETH on behalf of users who never directly interacted with Kelp.
  • Insurance fund drawdowns at protocols that integrated rsETH and now face redemption requests they cannot fully meet.
Composability Risk Is Now Forensic Risk

Holders of leveraged or yield-strategy positions across DeFi may have unexpected exposure to the Kelp DAO incident even without ever interacting with Kelp directly. Your forensic record needs to capture not just direct deposits, but any protocol position that used rsETH as a collateral asset at the time of the incident.


The On-Chain Laundering Trail

Within under 60 minutes of the drain, stolen ETH-denominated value was running through a recognizable, repeatable pipeline:

  1. Decomposition into ETH and large stablecoin lots via Uniswap V3 and CoW Protocol routes designed to minimize slippage on size. USDC was preferred to be exited quickly because of Circle's aggressive freeze posture; USDT was retained where stablecoin holding was needed.
  2. Splitting across multiple intermediary externally-owned addresses (EOAs), each holding a fragment of the stolen total. Lazarus has repeatedly used 5- to 12-wallet splits to slow analyst tracking and complicate freeze coordination.
  3. Bridging via THORChain and eXch — the same combination that handled Atomic Wallet, Stake.com, CoinEx, and the Bybit outflow tail.
  4. Conversion to native Bitcoin and entry into mixing infrastructure on the BTC side, where the trail becomes probabilistic rather than deterministic.
Stage Action Forensic Visibility
1. Drain Privileged transaction empties rsETH-backing collateral pool Deterministic — on-chain, fully visible
2. Decompose Swap to ETH and stablecoin lots via Uniswap, CoW Deterministic
3. Split Distribute across 5 to 12 fresh EOAs Deterministic — clusterable
4. Bridge THORChain and eXch routes to BTC Deterministic but cross-chain
5. Mix Tornado Cash, YoMix, or BTC CoinJoin Probabilistic — partial unwinding only
6. OTC Off-chain conversion through DPRK-affiliated brokers Off-chain — law enforcement and OSINT only

Stages 1 through 4 are where forensic intervention has the highest impact. The window is typically 12 to 72 hours. After that, mixing dominates and the recovery probability curve flattens.


Why Attribution Points to North Korea

On-chain signals

  • Splitting pattern. The 5- to 12-wallet split is operationally expensive and consistent with a disciplined actor running a controlled laundering process, not an opportunist.
  • Bridge selection. THORChain plus eXch is heavily DPRK-loaded relative to the broader cross-chain user base.
  • BTC end-state. Most opportunistic Ethereum attackers stay in ETH or stablecoins. Lazarus consistently terminates at Bitcoin.
  • Pacing. Funds were not dumped in one block. They were drained, swapped, and bridged in measured intervals across the first 12 to 48 hours, behavior that maximizes price-impact efficiency and complicates real-time tracking.

Off-chain signals

  • Initial access narrative. If the breach started with a fake job offer, a "coding interview", or a malicious npm package, the prior probability of DPRK involvement is unusually high.
  • Malware family identification from the targeted company's incident response — InvisibleFerret, BeaverTail, OdysseyStealer, or related Python loader strains map directly to known DPRK tradecraft.
  • FBI and CISA advisories. The US government's formal attribution carries more weight than any single private analyst's view.

OFAC Compliance Exposure for rsETH Holders

Forensic attribution to North Korea has direct legal consequences for everyone in the rsETH supply chain:

  • OFAC SDN listing means any US person or entity that knowingly transacts with funds traceable to a sanctioned address may face civil penalties, regardless of intent.
  • Tornado Cash and several DPRK-linked addresses are explicitly designated. Receiving funds that have passed through these services creates compliance exposure.
  • Stablecoin issuers are required to freeze sanctioned addresses on their respective chains, and have repeatedly done so for DPRK-linked wallets.
  • Centralized exchanges with US presence must screen incoming deposits against OFAC lists. Funds that touch flagged wallets may be frozen and reported to FinCEN regardless of the depositor's identity.
If You Hold or Held rsETH

Holders who acquired rsETH on the secondary market during or after the incident may need to document their acquisition trail to demonstrate clean provenance. Forensic firms can produce a chain-of-custody record for individual rsETH lots that may be needed for exchange deposits or for tax-loss documentation.


What to Do If You Held rsETH or Deposited in Kelp

  1. Document everything immediately. Record your wallet addresses, your deposit transaction hashes, your last-known rsETH balance, and the timestamps. Forensic recoverability depends on evidence quality.
  2. Map your indirect exposure. If you used rsETH as collateral in any other protocol (lending markets, perp DEXs, yield vaults), document those positions too. Cascading impact may matter as much as direct deposit.
  3. File with the FBI's IC3 at ic3.gov even if you believe the Kelp team will handle remediation. Individual victim filings raise the case priority and create the legal basis for later asset return.
  4. Engage an independent forensic investigator if you held a material position. The protocol team's investigation will focus on protocol-level facts; a victim-side investigation produces evidence that supports your specific claim against any future recovery pool.
  5. Do not respond to "recovery agents" contacting you over Telegram, X, or Discord. Lazarus and unrelated scam operators both run secondary scams targeting victims of headline incidents.
  6. Preserve all official communications from the Kelp team and any protocol that integrated rsETH. These will be relevant evidence in any future class proceeding or recovery distribution.

Frequently Asked Questions

Did North Korea hack Kelp DAO?
On-chain analysis of the post-drain wallet behavior, splitting pattern across multiple intermediary wallets, and bridging route through THORChain and eXch from the Kelp DAO incident closely matches the established Lazarus Group playbook attributed to North Korea's Reconnaissance General Bureau. Final attribution will be confirmed by federal authorities and forensic firms.
How was Kelp DAO hacked?
Initial indicators suggest the Kelp DAO incident was an operational compromise rather than a smart contract exploit. The attacker appears to have obtained access to a privileged role, potentially a deployer key, an upgrade-admin signer, or an oracle update authority, which allowed unauthorized withdrawals from the protocol's collateral pool.
What is rsETH and why does the Kelp DAO hack matter?
rsETH is the liquid restaking token issued by Kelp DAO, representing pooled ETH that has been restaked across multiple Actively Validated Services in the EigenLayer ecosystem. Because rsETH is increasingly used as collateral in lending protocols, perp DEXs, and yield vaults, a successful drain at the Kelp issuer level can cascade into liquidations, oracle de-pegs, and frozen collateral across protocols that never held the stolen funds directly.
Where did the stolen Kelp DAO funds go?
Stolen value was decomposed into ETH and stablecoin lots via Uniswap V3 and CoW Protocol routes designed to minimize slippage on size, split across multiple intermediary wallets, then bridged toward Bitcoin via THORChain and eXch. Conversion to native BTC and entry into mixing infrastructure on the BTC side is the typical Lazarus end-state.
Can stolen Kelp DAO funds be recovered?
Partial recovery is possible if stolen funds touch a cooperative centralized exchange before laundering completes, or if bridge operators and stablecoin issuers freeze tagged addresses. Recovery probability drops significantly once funds pass through Tornado Cash or comparable mixing infrastructure and reach OTC brokers.

Held rsETH or Deposited in Kelp DAO?

Wallet Witness is actively tracking the Kelp DAO incident on-chain. Direct holders and indirect rsETH-collateralized position holders both benefit from a victim-side forensic record. Initial case assessments are free.

Start a Free Case Review

Zack Coffing

Founder of Wallet Witness. Independent blockchain forensic investigator specializing in crypto scam analysis, digital asset tracing, and litigation support. Based in the United States, serving victims and attorneys worldwide.