LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has assigned blame for the $290 million Kelp DAO exploit to the protocol's own security configuration, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to deceive the verifier into confirming a fraudulent transaction. The…
April 20, 2026, 5:01 a.m.