LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, stating that the protocol's single-verifier setup, contrary to LayerZero's recommendations, was the key factor. The attack, linked to North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on, and then conducting a DDoS attack on other nodes to force a failover. This allowed the attackers to fraudulently release 116,500 rsETH. LayerZero emphasizes that the attack's success was due to Kelp's disregard of multi-verifier setup advice, which would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the exploit. The company has confirmed no contagion to other applications on the protocol and will no longer support single-verifier configurations.