LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the recent $290 million exploit of Kelp DAO to the protocol's own security configuration. According to LayerZero, Kelp's use of a single-verifier setup, despite recommendations for a multi-verifier configuration, made it vulnerable to attack. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. LayerZero emphasizes that the attack was only successful due to Kelp's single-verifier setup and notes that its own protocol worked as designed. The company has confirmed no contagion to other applications and will no longer support single-verifier configurations, pushing for a protocol-wide migration to multi-verifier setups. This incident highlights the importance of security configurations in DeFi protocols and the evolving tactics of malicious actors like Lazarus Group, which has been linked to over $575 million in DeFi exploits in just 18 days.