According to LayerZero's incident report disclosed on May 20, the rsETH cross-chain bridge built on LayerZero was attacked on April 18, 2026, resulting in the loss of approximately 116,500 rsETH, valued at around $292 million. Mandiant and CrowdStrike attributed the attack to North Korean-linked hacking group TraderTraitor (UNC4899).
The attackers obtained developers' session keys through social engineering starting in March, infiltrated LayerZero's RPC cloud environment to tamper with RPC node data, and launched DoS attacks on external RPC services. This forced DVNs to rely solely on compromised nodes for signing, enabling attackers to forge cross-chain messages. LayerZero identified the vulnerability's root cause as the "single validator" configuration used by the affected OApp. The protocol has since adjusted DVN strategies to reject serving as a sole validator and has fully rebuilt the compromised infrastructure.