LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, despite previous warnings, allowed the attack to occur. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and subsequently launched a DDoS attack on other nodes to force a failover. This led to the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup for added security. The company has confirmed no contagion to other applications on the protocol and will no longer support single-verifier setups, prompting a protocol-wide migration to multi-verifier configurations.