LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korean Hackers
LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, stating that the protocol's single-verifier setup, which was previously warned against, allowed the attack to occur. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack was only possible due to Kelp's 1-of-1 verifier configuration, which ignored LayerZero's recommendations for a multi-verifier setup. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken steps to prevent similar attacks in the future, including requiring a multi-verifier setup for all applications. The Lazarus Group has been linked to two major DeFi exploits in the past 18 days, draining over $575 million from DeFi protocols through different attack vectors.