LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously warned against, was the primary factor in the attack. The attackers, who LayerZero believes with preliminary confidence to be North Korea's Lazarus Group and its TraderTraitor subunit, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to falsely confirm a fraudulent transaction. This was possible because Kelp had not implemented a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The attack was facilitated by a distributed denial-of-service attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. LayerZero has confirmed that there was no contagion to other applications on the protocol and has stated that it will no longer sign messages for applications running a 1-of-1 configuration, effectively requiring a protocol-wide migration to multi-verifier setups. The exploit has been linked to the Lazarus Group, which has been implicated in another recent DeFi exploit, highlighting the group's ability to adapt its tactics and target different vulnerabilities in the DeFi space.