LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the recent $290 million Kelp DAO exploit to a security configuration flaw on Kelp's part, stating that the protocol's single-verifier setup made it vulnerable to attack. According to LayerZero, the attackers, who are believed to be associated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier, allowing them to fake a cross-chain transaction. The attack was only successful because Kelp had not implemented a multi-verifier setup, which would have required consensus across multiple independent verifiers to confirm a message. LayerZero had previously recommended this setup to Kelp, but it was not implemented. The company has confirmed that there was no contagion to other applications on the protocol and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.