LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has shifted the blame for the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which was previously warned against, made it vulnerable to attack. The exploit, attributed to North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on, allowing the attackers to create a fraudulent transaction. The attack was only possible because Kelp ignored recommendations to implement a multi-verifier setup, which would have required consensus across multiple independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since gone back online, announcing that it will no longer sign messages for applications running single-verifier configurations.