LayerZero Attributes $290 Million Kelp Exploit to Poor Security Setup and North Korean Hackers
LayerZero has attributed the recent $290 million exploit of Kelp DAO to the protocol's own security configuration, stating that the use of a single-verifier setup, despite previous warnings, made the attack possible. The attackers, believed to be affiliated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service attack on other nodes to force a failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack highlights the importance of using a multi-verifier setup with redundancy, which LayerZero had recommended to Kelp. The company has confirmed that no other applications on the protocol were affected and has announced that it will no longer support single-verifier setups. The breach is the second major exploit linked to the Lazarus Group in recent weeks, following the Drift Protocol exploit on April 1, and underscores the need for DeFi protocols to strengthen their defenses against increasingly sophisticated attacks.