LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Kelp's Setup as the Cause
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security setup, stating that the protocol's single-verifier configuration made it vulnerable to attack. The exploit was reportedly carried out by North Korea's Lazarus Group, who compromised two RPC nodes that LayerZero's verifier relied on and launched a DDoS attack on other nodes to force a failover. LayerZero had previously warned Kelp about the risks of a single-verifier setup and recommended a multi-verifier configuration for added security. The attack highlights the importance of robust security measures in DeFi protocols and the need for protocols to adapt quickly to emerging threats. The exploit has resulted in the loss of 116,500 rsETH, but LayerZero has confirmed that there is no contagion to other applications on the protocol. The company has also announced that it will no longer support single-verifier setups, prompting a protocol-wide migration to multi-verifier configurations.