LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Points to North Korea's Lazarus Group
LayerZero has shifted the blame for the $290 million Kelp DAO exploit to Kelp's alleged negligence in setting up its security, stating that the protocol's single-verifier configuration was the primary factor that allowed the attack to succeed. According to LayerZero, the attackers, who are believed to be affiliated with North Korea's Lazarus Group, targeted the infrastructure layer by compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service attack on the remaining nodes to force a failover to the compromised ones. This sophisticated attack was made possible by Kelp's failure to implement a multi-verifier setup with redundancy, a measure that LayerZero had explicitly recommended. As a result, LayerZero has announced that it will no longer support applications with single-verifier configurations, emphasizing the importance of robust security measures in preventing such exploits. The incident highlights the evolving threat landscape in DeFi and the need for protocols to prioritize security and adapt to emerging attack vectors.