LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup that the company had warned against. According to LayerZero, the attackers, who are believed to be associated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on to confirm cross-chain transactions. The attackers then launched a distributed denial-of-service attack on other external RPC nodes, forcing failover to the compromised nodes, which led to the release of 116,500 rsETH to the attackers. LayerZero notes that the attack would not have been successful if Kelp had implemented a multi-verifier setup with redundancy, as recommended. The company has confirmed that there was no contagion to other applications on the protocol and has since taken steps to prevent similar attacks in the future.