LayerZero Attributes $290 Million Kelp Exploit to Security Misconfiguration, Links Attackers to North Korea
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that the protocol's single-verifier setup, which was contrary to their recommendations, allowed the attack to occur. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on othe…
April 20, 2026, 5:01 a.m.