LayerZero Pins $290 Million Exploit on Kelp's Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, despite prior warnings, enabled the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, manipulating them to validate a fraudulent transaction while reporting accurate data to other systems. A DDoS attack on uncompromised nodes forced a failover to the poisoned ones, releasing 116,500 rsETH to the attackers. LayerZero emphasizes that the attack's success was contingent on Kelp's 1-of-1 verifier configuration, contrary to recommendations for a multi-verifier setup. The company has confirmed no contagion to other applications and will no longer support single-verifier configurations, underscoring the importance of security choices in preventing such exploits.