LayerZero Attributes $290 Million Kelp Exploit to Single-Verifier Setup and North Korea's Lazarus Group
LayerZero has identified Kelp's security setup as the primary cause of the $290 million exploit, stating that the protocol's single-verifier configuration, contrary to LayerZero's recommendations, allowed for the breach. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover, resulting in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful due to Kelp's decision to use a single-verifier setup, despite warnings, and that its own protocol functioned as designed. The company has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier configurations, and highlights the distinction between a protocol-level bug and a configuration failure by an integrator.