LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Kelp's Security Setup

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, despite previous warnings, made it vulnerable to attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack was only possible due to Kelp's 1-of-1 verifier configuration, which LayerZero had advised against, recommending a multi-verifier setup instead. LayerZero has confirmed that no other applications on the protocol were affected and has since taken measures to prevent similar attacks, including refusing to sign messages for applications with single-verifier setups. The incident highlights the importance of security configurations and the need for DeFi protocols to harden their defenses against evolving attack vectors.