LayerZero Attributes $290 Million Kelp DAO Exploit to Kelp's Security Configuration and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security setup, stating that the protocol's single-verifier configuration made it vulnerable to attack. According to LayerZero, the attackers, who are believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. The attack was only successful because Kelp had ignored LayerZero's recommendations to use a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.