LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which they had warned against, was exploited by attackers. The attackers, believed to be from North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. This allowed them to fraudulently release 116,500 rsETH to the attackers. The attack was only possible due to Kelp's 1-of-1 verifier configuration, and LayerZero had previously recommended a multi-verifier setup for added security. The company has confirmed that there was no contagion to other applications on the protocol and has since gone back online, but will no longer support single-verifier setups.