LayerZero Attributes $290 Million Kelp Exploit to Configuration Flaw and North Korean Hackers

LayerZero has attributed the $290 million exploit of Kelp DAO to a configuration flaw in Kelp's security setup, stating that the protocol's single-verifier configuration made it vulnerable to attack. According to LayerZero, the attackers, who are believed to be from North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service (DDoS) attack on other nodes to force a failover to the compromised ones. The attack was only successful because Kelp had not implemented a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero had previously recommended a multi-verifier setup to Kelp, but it was not implemented. The company has confirmed that there was no contagion to other applications on the protocol and has resumed operations, but will no longer support single-verifier configurations. The Lazarus Group has been linked to two major DeFi exploits in the past 18 days, including the Drift Protocol exploit on April 1, and has drained over $575 million from DeFi protocols during this time.