LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier security configuration, which the company had previously advised against. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes and launched a DDoS attack on other nodes to force a failover, resulting in the release of 116,500 rsETH to the attackers. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across multiple independent verifiers to confirm a message. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has announced that it will no longer support single-verifier configurations. The incident highlights the importance of robust security measures in DeFi protocols and the need for vigilance against evolving attack vectors.