LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, despite previous warnings, enabled the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack's success was made possible by Kelp's decision to run a 1-of-1 verifier configuration, which LayerZero had advised against. The company has confirmed that the attack did not affect any other applications on the protocol and has announced that it will no longer support single-verifier setups. The exploit highlights the importance of security configurations and the need for DeFi protocols to harden their defenses against evolving attack vectors.