LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration issue on Kelp's part, stating that the liquid restaking protocol's single-verifier setup made it vulnerable to attack. According to LayerZero, the attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service attack on other nodes to force a failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. LayerZero emphasizes that the attack was only successful because Kelp ignored recommendations for a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including no longer signing messages for applications with single-verifier setups.