LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the root cause of the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on the remainin…
April 20, 2026, 5:01 a.m.