LayerZero Attributes $290 Million Kelp Exploit to Poor Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, despite previous warnings, allowed the attack to occur. The attack, attributed to North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducting a distributed denial-of-service (DDoS) attack on other nodes to force failover to the compromised ones. This resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasized that the attack was only possible due to Kelp's 1-of-1 verifier configuration, which ignored recommendations for a multi-verifier setup with redundancy. The company has confirmed no contagion to other applications on the protocol and will no longer support single-verifier configurations.