LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security setup, stating that the use of a single-verifier configuration made it vulnerable to attack. The company had previously recommended a multi-verifier setup for added security. The attackers, believed to be part of North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to manipulate transaction data and ultimately steal 116,500 rsETH. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier configurations. The incident highlights the importance of robust security measures in DeFi protocols and the need for vigilance against evolving attack vectors.