LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier configuration, a setup the company had warned against. According to LayerZero, the attackers, believed to be associated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service (DDoS) attack on other nodes to force a failover to the compromised ones. The attackers then used the compromised nodes to trick LayerZero's verifier into releasing 116,500 rsETH. LayerZero emphasizes that the attack was only successful due to Kelp's use of a single-verifier setup, contrary to the company's recommendations for a multi-verifier configuration. The incident highlights the importance of security configurations in DeFi protocols and the evolving tactics of attackers like the Lazarus Group.