LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Configuration and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security setup, stating that the protocol's single-verifier configuration, contrary to their recommendations, allowed the attack to succeed. The attack, attributed with preliminary confidence to North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on, and then conducting a DDoS at…
April 20, 2026, 5:01 a.m.