LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to a vulnerability in Kelp's security configuration, specifically the use of a single-verifier setup that the company had warned against. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier, allowing them to fake a fraudulent transaction. The attack was only successful because Kelp had not implemented a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero's verifier relied on a mix of internal and external RPC nodes for redundancy, but the attackers used a distributed denial-of-service attack to force failover to the compromised nodes. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups. The exploit highlights the importance of robust security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated attacks.