LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, stating that the protocol's single-verifier setup, which it had warned against, was the primary cause of the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on the remaining nodes to force a failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack was only possible due to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the verifier offline, stating that it will no longer support single-verifier configurations. The exploit highlights the importance of robust security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated attacks.