LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Security Setup

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier setup, which they had warned against. The attack, attributed to North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on and launching a DDoS attack on other nodes. This allowed the attackers to trick LayerZero's verifier into confirming a fraudulent transaction. The attack was only possible because Kelp had not implemented a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer support single-verifier setups. The attack highlights the importance of robust security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated attacks.