LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korean Hackers

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, stating that Kelp's use of a single-verifier setup, despite recommendations for a multi-verifier setup, made it vulnerable to the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes and launched a distributed denial-of-service attack on the remaining nodes, allowing them to trick LayerZero's verifier into releasing 116,500 rsETH. The attack was made possible by Kelp's 1-of-1 verifier configuration, which meant that only one entity was verifying messages to and from the rsETH bridge. LayerZero had previously recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, making it more difficult for the attackers to forge a valid message. The company has confirmed that there was no contagion to other applications on the protocol and that every OFT-standard token and application running multi-verifier setups was unaffected. LayerZero's verifier is back online, and the company will no longer sign messages for applications running a 1-of-1 configuration, forcing a protocol-wide migration to multi-verifier setups. The exploit highlights the importance of robust security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated attacks.