LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has identified Kelp's single-verifier configuration as the primary cause of the $290 million exploit, stating that this setup, contrary to their recommendations, allowed attackers to compromise two RPC nodes and execute a DDoS attack on others, leading to the fraudulent release of 116,500 rsETH. The attackers, believed to be from North Korea's Lazarus Group, exploited this vulnerability…
April 20, 2026, 5:01 a.m.