LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, allowed the attack to occur. The attackers, believed to be from North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier and launched a distributed denial-of-service attack on the remaining nodes. This forced a failover to the compromised nodes, which then reported a fraudulent transaction, resulting in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful due to Kelp's single-verifier setup and notes that its own monitoring infrastructure was not compromised. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support single-verifier configurations.