LayerZero Attributes $290 Million Kelp DAO Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup made it vulnerable to attack. The exploit was carried out by compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducting a distributed denial-of-service attack on other nodes to force failover to the compromised ones. LayerZero had previously warned Kelp against using a single-verifier setup, recommending a multi-verifier configuration for added security. The attack has been attributed with preliminary confidence to North Korea's Lazarus Group, which has also been linked to the Drift Protocol exploit on April 1. LayerZero has confirmed that the attack only worked because of Kelp's 1-of-1 verifier configuration and has stated that it will no longer sign messages for applications running a 1-of-1 configuration, forcing a protocol-wide migration to multi-verifier setups.