LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the recent $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup made it vulnerable to attack. The attackers, believed to be affiliated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, allowing them to manipulate the system and steal funds. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across multiple independent verifiers to confirm a message. LayerZero had previously recommended this setup to Kelp, but it was not implemented. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.