LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has identified the cause of the $290 million Kelp DAO exploit as Kelp's own security configuration, specifically the use of a single-verifier setup despite prior warnings. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover. This allowed them to manipulate the system into releasing 116,500 rsETH to the attackers. The attack's success is attributed to Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero had recommended this setup, and the company will no longer support applications with single-verifier configurations. The incident highlights the importance of robust security measures in DeFi protocols and the need for vigilance against increasingly sophisticated attacks.