LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links It to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's single-verifier security configuration, which the company had previously advised against. The attack, believed to be the work of North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on, and then launching a DDoS attack on other nodes to force a failover. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack's success is attributed to Kelp's use of a 1-of-1 verifier configuration, despite recommendations for a multi-verifier setup. LayerZero has confirmed that no other applications on the protocol were affected and has stated that it will no longer support single-verifier configurations.