LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the liquid restaking protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, exploited a novel vector targeting the infrastructure layer rather than any protocol code. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping their binary software with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction. This was made possible because Kelp had ignored recommendations for a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken steps to prevent similar attacks, including refusing to sign messages for applications with single-verifier configurations.