LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korean Hackers

LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor. The attack, attributed to North Korea's Lazarus Group, exploited a novel vector targeting the infrastructure layer, compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. This allowed the attackers to manipulate the system into releasing 116,500 rsETH. The attack's success was facilitated by Kelp's failure to implement a multi-verifier setup with redundancy, as recommended by LayerZero. The company has confirmed that the attack did not affect any other applications on the protocol and has announced that it will no longer support single-verifier configurations, prompting a protocol-wide migration to more secure setups.