LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has shifted the blame for the $290 million Kelp DAO exploit to Kelp's security setup, stating that the protocol's single-verifier configuration, which was contrary to LayerZero's recommendations, made it vulnerable to the attack. The attackers, believed to be from North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service attack on other nodes to force a failover to the compromised ones. This allowed the attackers to release 116,500 rsETH. LayerZero emphasizes that the attack would not have been successful if Kelp had implemented a multi-verifier setup with redundancy, as recommended. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier configurations.