LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, contrary to LayerZero's recommendations, was the vulnerability exploited by the attackers. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducted a distributed denial-of-service attack on other nodes to force a failover to the compromised ones. This allowed the attackers to release 116,500 rsETH. LayerZero emphasizes that its protocol functioned as designed and that the exploit was only possible due to Kelp's security choices. The company has confirmed no contagion to other applications and will no longer support single-verifier setups.