LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on, and then launching a DDoS attack on other nodes to force a failover. This allowed the attackers to trick LayerZero's verifier into confirming a fraudulent transaction, resulting in the release of 116,500 rsETH. LayerZero emphasizes that the attack was only successful because of Kelp's single-verifier setup and notes that its own protocol worked as designed, with the issue stemming from Kelp's security choices rather than any flaw in LayerZero's code. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.