LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero attributes the $290 million Kelp DAO exploit to Kelp's security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier setup. The attack, linked to North Korea's Lazarus Group, involved compromising two RPC nodes and launching a DDoS attack on other nodes to force failover, allowing the attackers to fraudulently release 116,500 rsETH. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that its own protocol and code were not at fault. The company has confirmed no contagion to other applications and will no longer support single-verifier setups.