LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service attack on the remaining nodes to force a failover to the compromised nodes. This allowed the attackers to steal 116,500 rsETH. LayerZero has confirmed that the attack only worked due to Kelp's 1-of-1 verifier configuration and has stated that it will no longer support single-verifier setups. The company has also confirmed that there was no contagion to other applications on the protocol, and that all OFT-standard tokens and applications running multi-verifier setups were unaffected. The LayerZero Labs verifier is back online, and the company is pushing for a protocol-wide migration to multi-verifier setups. This incident highlights the importance of security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated attacks.