LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, despite prior warnings, was the vulnerability that led to the attack. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover. This allowed the attackers to deceive LayerZero's verifier into releasing 116,500 rsETH. The attack's success is attributed to Kelp's decision to run a 1-of-1 verifier configuration, ignoring recommendations for a multi-verifier setup. LayerZero has confirmed that no other applications on the protocol were affected and has since ceased signing messages for applications with single-verifier setups, prompting a protocol-wide migration to multi-verifier configurations. The distinction between a protocol-level bug and a configuration failure is crucial for how DeFi prices LayerZero risk. Meanwhile, Lazarus Group has been linked to over $575 million in DeFi exploits within 18 days, adapting its tactics faster than DeFi protocols can enhance their defenses.