LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier setup, which the company had previously advised against. The attack, linked to North Korea's Lazarus Group, exploited this configuration by compromising two RPC nodes that LayerZero's verifier relied on, then launching a DDoS attack on other nodes to force a failover to the compromised ones. This allowed the attackers to deceive LayerZero's verifier into releasing 116,500 rsETH. The incident highlights the importance of a multi-verifier setup, as LayerZero's own monitoring infrastructure was bypassed due to the selective manipulation of data on the compromised nodes. LayerZero has confirmed that no other applications on the protocol were affected and will no longer support single-verifier configurations, prompting a protocol-wide migration to more secure setups. The Lazarus Group's involvement marks its second major exploit in 18 days, following the Drift Protocol breach, demonstrating the group's rapid adaptation of attack strategies and the need for DeFi protocols to enhance their defenses.