LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's inadequate security configuration, specifically its use of a single-verifier setup. This setup, which LayerZero had warned against, allowed attackers to compromise two remote procedure call (RPC) nodes and launch a distributed denial-of-service (DDoS) attack on other nodes. The attackers, believed to be associated with North Korea's Lazarus Group, manipulated the compromised nodes to deceive LayerZero's verifier into releasing 116,500 rsETH. The attack's success was contingent upon Kelp's single-verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier setups.