LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause. The attack, attributed to North Korea's Lazarus Group with preliminary confidence, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false transaction data to LayerZero's verifier while providing accurate data to other systems, making the attack invisible to LayerZero's monitoring. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that a multi-verifier setup, as recommended, would have prevented the exploit. The company has confirmed no contagion to other applications on the protocol and has taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier setups.