LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier setup, which the company had previously warned against. The attack, allegedly carried out by North Korea's Lazarus Group, involved the compromise of two RPC nodes used by LayerZero's verifier to confirm cross-chain transactions. These nodes were swapped with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction, while reporting accurate data to other systems. To ensure the attack remained undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. The attack's success is directly linked to Kelp's decision to operate a single-verifier setup, contrary to LayerZero's recommendations for a multi-verifier configuration with redundancy. LayerZero has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar attacks, including refusing to sign messages for applications with single-verifier setups. The incident highlights the importance of robust security configurations and the evolving threats posed by groups like Lazarus, which has been linked to over $575 million in DeFi losses in under three weeks.