LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which was previously warned against, allowed the attack to occur. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. This allowed the attackers to fake a valid cross-chain transaction, resulting in the release of 116,500 rsETH. LayerZero emphasizes that the attack was only successful due to Kelp's 1-of-1 verifier configuration and notes that a multi-verifier setup would have prevented the exploit. The company has confirmed that there is no contagion to other applications on the protocol and will no longer support single-verifier configurations.