LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the responsibility for the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, made it vulnerable to the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, allowing them to manipulate the system into releasing 116,500 rsETH. The attack was made possible by Kelp's decision to ignore LayerZero's recommendations for a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the verifier offline, announcing that it will no longer support single-verifier configurations. The exploit highlights the importance of robust security measures in DeFi protocols and the need for vigilance against evolving attack vectors.