Skip to main content
Mallory
Back to stories
cryptocurrency-platform-riskstate-sponsored-espionageidentity-impersonation-fraudthird-party-vendor-breach

Zerion and KelpDAO link security incidents to DPRK TraderTraitor activity

Updated 6d agoFirst seen Apr 15, 202614 sources

Zerion published a security incident post-mortem, and LayerZero later issued a KelpDAO incident statement, with both incidents being publicly tied in threat-intelligence discussion to DPRK activity. Social-media reporting around the disclosures specifically associated the KelpDAO case with TraderTraitor, the North Korean cluster known for targeting cryptocurrency and Web3 organizations through social engineering and wallet compromise.

The available references do not provide technical indicators, loss figures, or a detailed attack chain, but they place both disclosures in the context of crypto-focused intrusions attributed to North Korean operators. For CISOs in digital-asset, DeFi, and wallet ecosystems, the incidents reinforce the ongoing risk from DPRK-linked campaigns that exploit trusted workflows, third-party relationships, and user-facing transaction processes to gain access and move funds.

Share:
Zerion and KelpDAO link security incidents to DPRK TraderTraitor activity
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the earliest known activity through the most recent confirmed update.

7 EVENTS
Apr 15, 20261mo ago

Zerion publishes security incident post-mortem

Zerion published a "Security Incident: Post Mortem" referenced in a 2026-04-15 Bluesky post. The available content does not provide further details on the incident, impact, or attribution.

Apr 20, 202628d ago

LayerZero publishes KelpDAO incident statement

LayerZero published a "KelpDAO Incident Statement" referenced in a 2026-04-20 Bluesky post. The post's hashtags suggest a cybersecurity incident possibly linked to DPRK-related threat activity, but no substantive incident details are provided in the available content.

Apr 21, 202627d ago

KelpDAO publishes additional context on April 18 incident

KelpDAO published an item titled 'April 18 Incident: Additional Context,' indicating a follow-up disclosure about the incident. The available reference does not provide substantive technical or impact details beyond the existence of this additional context statement.

Post by @lazarusholic.bsky.social - Bluesky
Apr 22, 202626d ago

KelpDAO attacker reportedly moves $175M to new addresses

An Arkm research item shared on Bluesky reported that funds linked to the KelpDAO hacker were transferred to new cryptocurrency addresses. The reported movement involved $175 million and occurred on 2026-04-22, indicating post-incident laundering or fund relocation activity.

Post by @lazarusholic.bsky.social - Bluesky
Apr 24, 202624d ago

Analysis reports laundering of $292M tied to KelpDAO theft

A referenced article titled "Where did the kelp $292m go? anatomy of a $292m laundering" reported on laundering activity involving $292 million linked to the KelpDAO incident. The available post provides no further technical details, but it indicates a broader accounting of stolen-fund movement than earlier reports of transfers to new addresses.

Post by @lazarusholic.bsky.social - Bluesky
May 6, 202612d ago

KelpDAO publishes LayerZero bridge hack clarification

KelpDAO published a statement titled "Setting the Record Straight Around the LayerZero Bridge Hack," indicating a further official clarification related to the incident. The available reference does not provide substantive new technical, impact, or attribution details beyond the existence of this follow-up statement.

Post by @lazarusholic.bsky.social - Bluesky
May 9, 20269d ago

LayerZero publishes follow-up update on KelpDAO incident

A Bluesky post on 2026-05-09 references a publication titled "LayerZero Update" by LayerZero. The available content does not include the substance of the update, but it indicates a new official follow-up communication related to the KelpDAO/LayerZero incident.

Post by @lazarusholic.bsky.social - Bluesky
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.