LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which was previously warned against, was the primary cause of the breach. The attackers, believed to be from North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions, and then launched a distributed denial-of-service (DDoS) attack on other nodes to force a failover to the compromised ones. This allowed the attackers to release 116,500 rsETH. The incident highlights the importance of a multi-verifier setup, as recommended by LayerZero, to prevent such attacks. LayerZero has confirmed no contagion to other applications on the protocol and will no longer support single-verifier configurations.