LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Security Configuration

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The exploit, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false data to LayerZero's verifier while continuing to provide accurate data to other systems. To prevent detection, the attackers also launched a distributed denial-of-service (DDoS) attack on other external RPC nodes, forcing LayerZero's verifier to fail over to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful due to Kelp's 1-of-1 verifier configuration, which it had warned against, and recommends a multi-verifier setup for increased security. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.